First published: Sun Apr 16 2023(Updated: )
XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xwiki | >=13.10.8<13.10.11 | |
Xwiki | >=14.4.3<14.4.7 | |
Xwiki | =14.6 | |
Xwiki | =14.10-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29506 has been categorized as a critical vulnerability due to the potential for code injection via authenticated endpoints.
To mitigate CVE-2023-29506, upgrade to XWiki version 13.10.11, 14.4.7, or 14.10.
Versions 13.10.8 to 13.10.10, 14.4.3 to 14.4.6, as well as 14.6 and 14.10-rc1 are vulnerable to CVE-2023-29506.
CVE-2023-29506 can allow attackers to perform unauthorized code injection attacks through crafted URLs.
Yes, the issue has been patched in XWiki versions 13.10.11, 14.4.7, and 14.10.