CVE-2023-29506

Source
https://cve.org/CVERecord?id=CVE-2023-29506
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29506.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-29506
Aliases
Published
2023-04-16T06:49:51.376Z
Modified
2026-08-12T04:05:45.730026362Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticated endpoints
Details

XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29506.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/xwiki/xwiki-commons

Affected ranges

Type
GIT
Repo
https://github.com/xwiki/xwiki-commons
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:xwiki:xwiki:14.6:*:*:*:*:*:*:*"
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "extracted_events": [
        {
            "introduced": "13.10.8"
        },
        {
            "fixed": "13.10.11"
        },
        {
            "introduced": "14.4.3"
        },
        {
            "fixed": "14.4.7"
        },
        {
            "introduced": "14.6"
        },
        {
            "last_affected": "14.6"
        }
    ]
}
Type
GIT
Repo
https://github.com/xwiki/xwiki-platform
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:xwiki:xwiki:14.6:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "13.10.8"
        },
        {
            "fixed": "13.10.11"
        },
        {
            "introduced": "14.4.3"
        },
        {
            "fixed": "14.4.7"
        },
        {
            "introduced": "14.6"
        },
        {
            "last_affected": "14.6"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

14.*
14.6
xwiki-commons-13.*
xwiki-commons-13.10.10
xwiki-commons-13.10.8
xwiki-commons-13.10.9
xwiki-commons-14.*
xwiki-commons-14.4.3
xwiki-commons-14.4.4
xwiki-commons-14.4.5
xwiki-commons-14.4.6
xwiki-commons-14.6
xwiki-platform-14.*
xwiki-platform-14.4.3
xwiki-platform-14.4.4
xwiki-platform-14.4.5
xwiki-platform-14.4.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29506.json"