Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Arbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xml
Vulnerability Description
org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service. The problem has been patched in versions 12.10.10, 13.4.4, and 13.8-rc-1. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Vulnerability Title
XWiki Commons代码问题漏洞
Vulnerability Description
XWiki Commons是其他几个顶级 XWiki 项目共有的技术库。 XWiki Commons存在安全漏洞,该漏洞源于脚本可以访问通过 XML 脚本通过 XML 外部实体注入运行 XWiki 应用程序服务器的用户访问的任何文件服务。以下产品和版本受到影响:>= 2.7、< 13.4.4、< 13.8、< 12.10.10。
CVSS Information
N/A
Vulnerability Type
N/A