CVE-2023-27480: Data leak through a XAR import XXE attack in xwiki-platform-xar-model
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display the content of any file on the XWiki server host. This vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10-rc-1. Users are advised to upgrade. Users unable to upgrade may apply the patch e3527b98fd manually.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27480?
The severity of CVE-2023-27480 is considered high due to its potential impact on user data and security.
How do I fix CVE-2023-27480?
To fix CVE-2023-27480, upgrade to XWiki version 14.4.8 or later, or any version beyond the affected ranges.
Who is affected by CVE-2023-27480?
CVE-2023-27480 affects any user with edit rights on documents in specific versions of XWiki Platform.
What type of vulnerability is CVE-2023-27480?
CVE-2023-27480 is a vulnerability that allows users to exploit file imports via forged XAR files.
What are the potential consequences of CVE-2023-27480?
The potential consequences of CVE-2023-27480 include unauthorized access to sensitive files and data leakage.