CVE-2023-29211: org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights WikiManager.DeleteWiki can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the wikiId url parameter. The problem has been patched on XWiki 13.10.11, 14.4.7, and 14.10.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29211?
CVE-2023-29211 is classified as a critical vulnerability due to its ability to allow arbitrary code execution.
How do I fix CVE-2023-29211?
To fix CVE-2023-29211, upgrade XWiki to versions 13.10.11, or any version from 14.4.8 onwards.
Who is affected by CVE-2023-29211?
CVE-2023-29211 affects users with view rights `WikiManager.DeleteWiki` in specified versions of XWiki.
What type of attacks can be executed through CVE-2023-29211?
CVE-2023-29211 allows attackers to execute arbitrary Groovy, Python, or Velocity code.
Is there a workaround for CVE-2023-29211?
No official workaround is recommended for CVE-2023-29211; upgrading to a secure version is advised.