CVE-2023-29506

Source
https://cve.org/CVERecord?id=CVE-2023-29506
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29506.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-29506
Aliases
Published
2023-04-16T06:49:51.376Z
Modified
2026-03-14T12:06:55.771802Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticated endpoints
Details

XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29506.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/xwiki/xwiki-platform

Affected ranges

Type
GIT
Repo
https://github.com/xwiki/xwiki-platform
Events
Database specific
{
    "versions": [
        {
            "introduced": "13.10.8"
        },
        {
            "fixed": "13.10.11"
        }
    ]
}
Type
GIT
Repo
https://github.com/xwiki/xwiki-platform
Events
Database specific
{
    "versions": [
        {
            "introduced": "14.4.3"
        },
        {
            "fixed": "14.4.7"
        }
    ]
}
Type
GIT
Repo
https://github.com/xwiki/xwiki-platform
Events
Database specific
{
    "versions": [
        {
            "introduced": "14.6"
        },
        {
            "fixed": "14.10"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29506.json"