Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9jq5-xwqw-q8j3: XWiki Platform vulnerable to page render failure due to broken translations

Impact

It’s possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object.

Patches

The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.

Workarounds

There is no other workaround other than fixing any way to create a document that fail to load.

References

https://jira.xwiki.org/browse/XWIKI-20460

For more information

If you have any questions or comments about this advisory:

ghsa
#vulnerability#git#java#jira#maven

Package

maven org.xwiki.platform:xwiki-platform-localization-source-wiki (Maven)

Affected versions

>= 4.3-milestone-2, < 13.10.11

>= 14.0-rc-1, < 14.4.8

>= 14.5, < 14.10.1

Patched versions

13.10.11

14.4.8

14.10.1

Description

Impact

It’s possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object.

Patches

The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.

Workarounds

There is no other workaround other than fixing any way to create a document that fail to load.

References

https://jira.xwiki.org/browse/XWIKI-20460

For more information

If you have any questions or comments about this advisory:

  • Open an issue in Jira XWiki.org
  • Email us at Security Mailing List

References

  • GHSA-9jq5-xwqw-q8j3
  • https://nvd.nist.gov/vuln/detail/CVE-2023-29520
  • https://jira.xwiki.org/browse/XWIKI-20460

tmortagne published to xwiki/xwiki-platform

Apr 18, 2023

Published to the GitHub Advisory Database

Apr 20, 2023

Reviewed

Apr 20, 2023

Last updated

Apr 20, 2023

Related news

CVE-2023-29520: It's possible to break many translations of a wiki

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. This will lead to a broken page. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. Users are advised to upgrade. There are no workarounds other than fixing any way to create a document that fail to load.