QID 983847
QID 983847: Java (maven) Security Update for org.xwiki.platform:xwiki-platform-rendering-wikimacro-store (GHSA-v662-xpcc-9xf6)
Security update has been released for org.xwiki.platform:xwiki-platform-rendering-wikimacro-store to fix the vulnerability. Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
The `{{wikimacrocontent}}` executes the content with the rights of the wiki macro author instead of the caller of that wiki macro. This makes possible to inject scripts through it and they will be executed with the rights of the wiki macro (very often a user which has Programming rights). Fortunately, no such macro exists by default in XWiki Standard but one could have been created or installed with an extension.
Solution
It has been patched in versions XWiki 12.6.3, 11.10.11 and 12.8-rc-1.Workaround:
There is no easy workaround other than disabling the affected macros. Inserting content in a safe way or knowing what is the user who called the wiki macro is not easy.
There is no easy workaround other than disabling the affected macros. Inserting content in a safe way or knowing what is the user who called the wiki macro is not easy.
Vendor References
- GHSA-v662-xpcc-9xf6 -
github.com/advisories/GHSA-v662-xpcc-9xf6
CVEs related to QID 983847
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v662-xpcc-9xf6 | org.xwiki.platform:xwiki-platform-rendering-wikimacro-store |
|