CVE-2026-23734
⚪ Do wiadomości
Wykorzystanie podatności w XWiki umożliwia dostęp do plików konfiguracyjnych przez przejście ścieżki.
CVSS
0.0
EPSS
19.6%
Exploit
none
Vendor
Opis źródłowy (NVD)
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnerability is can be exploited via resources parameter the ssx and jsx endpoints by using leading slashes. This issue has been patched in 18.1.0-rc-1, 17.10.3, 17.4.9, 16.10.17.
path-traversal
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 19.6% |
| Opublikowano (NVD) | 2026-05-20 20:16:36 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-23 12:10:00 UTC |
Referencje
- https://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d672df64429bf (security-advisories@github.com)
- https://github.com/xwiki/xwiki-commons/security/advisories/GHSA-xq3r-2qv5-vqqm (security-advisories@github.com)
- https://jira.xwiki.org/browse/XCOMMONS-3547 (security-advisories@github.com)