QID 995714

Date Published: 2023-10-26

QID 995714: Java (Maven) Security Update for org.xwiki.platform:xwiki-core-rendering-macro-footnotes (GHSA-35j5-m29r-xfq5)

The footnote macro executed its content in a potentially different context than the one in which it was defined. In particular in combination with the include macro, this allows privilege escalation from a simple user account in XWiki to programming rights and thus remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki installation.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Refer to Github security advisory GHSA-35j5-m29r-xfq5 for updates and patch information.
    Vendor References

    CVEs related to QID 995714

    Software Advisories
    Advisory ID Software Component Link
    GHSA-35j5-m29r-xfq5 org.xwiki.platform:xwiki-core-rendering-macro-footnotes URL Logo github.com/advisories/GHSA-35j5-m29r-xfq5