QID 994980
QID 994980: Java (Maven) Security Update for com.xpn.xwiki.platform.plugins:xwiki-plugin-scheduler (GHSA-8xhr-x3v8-rghj)
XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job script to a document doesn't modify the content author. Together with a CSRF vulnerability in the job scheduler, this can be exploited for remote code execution by an attacker with edit right on the wiki.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-8xhr-x3v8-rghj for updates and patch information.
Vendor References
- GHSA-8xhr-x3v8-rghj -
github.com/advisories/GHSA-8xhr-x3v8-rghj
CVEs related to QID 994980
Software Advisories
| Advisory ID | Software | Component | Link |
|---|