github.com
https://github.com/xwiki/xwiki-platform CVE-2024-31987
CRITICAL
XWiki Platform remote code execution from account via custom skins support
Record summary
CVE-2024-31987 has a selected CVSS score of 10.0 (critical).
Description
XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus allowing remote code execution. This has been patched in XWiki 14.10.19, 15.5.4 and 15.10RC1. No known workarounds are available except for upgrading.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 20, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
xwiki-platformBrowse xwiki / xwiki-platformDefault status: unknown | CVE List | 6.4-milestone-1 to < 14.10.19 | affected |
| 15.0-rc-1 to < 15.5.4 | affected | ||
| 15.6-rc-1 to < 15.10-rc-1 | affected | ||
| >= 6.4-milestone-1, < 14.10.19 | affected | ||
| >= 15.0-rc-1, < 15.5.4 | affected | ||
| >= 15.6-rc-1, < 15.10-rc-1 | affected | ||
org.xwiki.platform:xwiki-platform-oldcoreBrowse Maven / org.xwiki.platform:xwiki-platform-oldcore | GitHub Advisory | 6.4-milestone-1 to < 14.10.19 · Fixed in 14.10.19 | affected |
| 15.0-rc-1 to < 15.5.4 · Fixed in 15.5.4 | affected | ||
| 15.6-rc-1 to < 15.10-rc-1 · Fixed in 15.10-rc-1 | affected |
References
7github.com
https://github.com/xwiki/xwiki-platform/commit/3d4dbb41f52d1a6e39835cfb1695ca6668605a39 github.com
https://github.com/xwiki/xwiki-platform/commit/626d2a5dbf95b4e719ae13bf1a0a9c76e4edd5a2 github.com
https://github.com/xwiki/xwiki-platform/commit/da177c3c972e797d92c1a31e278f946012c41b56 github.comConfirmation
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-cv55-v6rw-7r5v jira.xwiki.org
https://jira.xwiki.org/browse/XWIKI-21478 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-31987