QID 995843
Date Published: 2023-11-08
QID 995843: Java (Maven) Security Update for org.xwiki.platform:xwiki-platform-display-api (GHSA-rmxw-c48h-2vf5)
In XWiki Platform, it's possible for a user to write a script in which any velocity content is executed with the right of any other document content author.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rmxw-c48h-2vf5 for updates and patch information.
Vendor References
- GHSA-rmxw-c48h-2vf5 -
github.com/advisories/GHSA-rmxw-c48h-2vf5
CVEs related to QID 995843
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rmxw-c48h-2vf5 | org.xwiki.platform:xwiki-platform-display-api |
|