CVE-2023-29214: org.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included pages in the IncludedDocuments panel. The problem has been patched on XWiki 14.4.7, and 14.10.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29214?
CVE-2023-29214 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2023-29214?
To fix CVE-2023-29214, upgrade your XWiki installation to a version above 13.10.11 or from 14.4.0 and below 14.4.7.
Who is affected by CVE-2023-29214?
Any user with edit rights on XWiki installations is potentially affected by CVE-2023-29214.
What types of code can be executed due to CVE-2023-29214?
CVE-2023-29214 allows execution of arbitrary Groovy, Python, or Velocity code in affected XWiki installations.
What component of XWiki is vulnerable in CVE-2023-29214?
CVE-2023-29214 affects the XWiki Commons libraries used in multiple XWiki projects.