CVE-2023-29520
published 2023-04-19CVE-2023-29520: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.53%
40.7th percentile
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. This will lead to a broken page. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. Users are advised to upgrade. There are no workarounds other than fixing any way to create a document that fail to load.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xwiki | xwiki | < 13.10.11 | 13.10.11 |
| xwiki | xwiki | >= 14.0 < 14.4.8 | 14.4.8 |
| xwiki | xwiki | >= 14.5 < 14.10.1 | 14.10.1 |
| xwiki | xwiki-platform | < 13.10.11 | 13.10.11 |
| xwiki | xwiki-platform | — | — |
| xwiki | xwiki-platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
XWiki Platform vulnerable to page render failure due to broken translations
osv·2023-04-20
CVE-2023-29520 [MEDIUM] XWiki Platform vulnerable to page render failure due to broken translations
XWiki Platform vulnerable to page render failure due to broken translations
### Impact
It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object.
### Patches
The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.
### Workarounds
There is no other workaround other than fixing any way to create a document that fail to load.
### References
https://jira.xwiki.org/browse/XWIKI-20460
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:[email protected])
GHSA
XWiki Platform vulnerable to page render failure due to broken translations
ghsa·2023-04-20
CVE-2023-29520 [MEDIUM] CWE-248 XWiki Platform vulnerable to page render failure due to broken translations
XWiki Platform vulnerable to page render failure due to broken translations
### Impact
It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object.
### Patches
The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.
### Workarounds
There is no other workaround other than fixing any way to create a document that fail to load.
### References
https://jira.xwiki.org/browse/XWIKI-20460
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:[email protected])
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-19
Published