QID 995845
Date Published: 2023-11-08
QID 995845: Java (Maven) Security Update for org.xwiki.platform:xwiki-platform-oldcore (GHSA-g2qq-c5j9-5w5w)
In XWiki Platform, it's possible for a user to execute any content with the right of an existing document's content author, provided the user have edit right on it. The reason for this is that the edit action sets the content without modifying the content author.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-g2qq-c5j9-5w5w for updates and patch information.
Vendor References
- GHSA-g2qq-c5j9-5w5w -
github.com/advisories/GHSA-g2qq-c5j9-5w5w
CVEs related to QID 995845
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g2qq-c5j9-5w5w | org.xwiki.platform:xwiki-platform-oldcore |
|