XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display the content of any file on the XWiki server host. This vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10-rc-1. Users are advised to upgrade. Users unable to upgrade may apply the patch e3527b98fd manually.
{
"cwe_ids": [
"CWE-611"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27480.json"
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"10682044994582062209395355451274672889",
"316620889823682004139978657038944998961",
"165670364901071670780639859061207895229",
"193219626044287465242543472079068701309"
]
},
"id": "CVE-2023-27480-1f6aec8c",
"source": "https://github.com/xwiki/xwiki-platform/commit/e3527b98fdd8dc8179c24dc55e662b2c55199434",
"signature_type": "Line",
"target": {
"file": "xwiki-platform-core/xwiki-platform-xar/xwiki-platform-xar-model/src/main/java/org/xwiki/xar/XarPackage.java"
},
"signature_version": "v1",
"deprecated": false
},
{
"digest": {
"length": 770.0,
"function_hash": "210754764101707908339566021559086432122"
},
"id": "CVE-2023-27480-dc53cf40",
"source": "https://github.com/xwiki/xwiki-platform/commit/e3527b98fdd8dc8179c24dc55e662b2c55199434",
"signature_type": "Function",
"target": {
"file": "xwiki-platform-core/xwiki-platform-xar/xwiki-platform-xar-model/src/main/java/org/xwiki/xar/XarPackage.java",
"function": "readDescriptor"
},
"signature_version": "v1",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27480.json"