QID 995714
Date Published: 2023-10-26
QID 995714: Java (Maven) Security Update for org.xwiki.platform:xwiki-core-rendering-macro-footnotes (GHSA-35j5-m29r-xfq5)
The footnote macro executed its content in a potentially different context than the one in which it was defined. In particular in combination with the include macro, this allows privilege escalation from a simple user account in XWiki to programming rights and thus remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki installation.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-35j5-m29r-xfq5 for updates and patch information.
Vendor References
- GHSA-35j5-m29r-xfq5 -
github.com/advisories/GHSA-35j5-m29r-xfq5
CVEs related to QID 995714
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-35j5-m29r-xfq5 | org.xwiki.platform:xwiki-core-rendering-macro-footnotes |
|