First published: Fri Mar 07 2025(Updated: )
### Impact The homepage of the application is public which enables a guest to download the package which might contain sensitive information. ### Patches 1.11.7 ### Workarounds The access to the page can be manually restricted to a specific set of users or groups.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
XWiki Confluence Migrator Pro | <1.11.7 | |
maven/com.xwiki.confluencepro:application-confluence-migrator-pro-ui | <=1.11.6 | 1.11.7 |
XWiki Confluence Migrator | <1.11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27604 has a severity level that indicates potential exposure of sensitive information due to unauthorized package downloads.
To fix CVE-2025-27604, upgrade XWiki Confluence Migrator Pro to version 1.11.7 or later.
CVE-2025-27604 addresses a public exposure vulnerability allowing guests to download potentially sensitive package contents.
Users of XWiki Confluence Migrator Pro versions prior to 1.11.7 are affected by CVE-2025-27604.
CVE-2025-27604 was disclosed in 2025, highlighting the vulnerability present before the fix in version 1.11.7.