XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API. This is fixed in version 16.10.7.
The flaw classified as CWE-23 (path traversal) consists of improper path validation in the webjars API of the XWiki platform. An attacker can construct an appropriate HTTP request to this API to escape the allowed directory and read application configuration files. The vulnerability is accessible remotely without the need for an account in the system.
An attacker can gain unauthorized access to XWiki configuration files, which may contain credentials, API keys, database connection parameters, and other sensitive configuration information. Disclosure of this data can lead to further system compromise.
XWiki Platform should be updated to version 16.10.7 or later, in which the vulnerability has been fixed. The patch is available in the project's GitHub repository (commit 9e7b4c03f2143978d891109a17159f73d4cdd318).
XWiki Platform in versions from 6.1-milestone-2 to 16.10.6 inclusive.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XXwiki
APPXwiki6.16.2 – 16.10.7 (excl.)17.0.0 – 17.3.0
Related vulnerabilities
XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch
XWiki Platform — path traversal umożliwia odczyt plików konfiguracyjnych
SQL Injection w XWiki Platform via parametr sort w getdeleteddocuments.vm
XWiki Rendering: bypass trybu restricted przez zagnieżdżone makra
XWiki Rendering: XSS przez składnię xdom+xml/current w XHTML