XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of service issue via CPU consumption. This vulnerability has been patched in XWiki 14.10.18, 15.5.3 and 15.8 RC1.
{
"cwe_ids": [
"CWE-400"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21651.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "14.10"
},
{
"fixed": "14.10.18"
},
{
"introduced": "15.5"
},
{
"fixed": "15.5.3"
},
{
"introduced": "15.6"
},
{
"fixed": "15.8"
}
]
}{
"cpe": "cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "14.10"
},
{
"fixed": "14.10.18"
},
{
"introduced": "15.5"
},
{
"fixed": "15.5.3"
},
{
"introduced": "15.6"
},
{
"fixed": "15.8"
}
]
}