CVE-2024-31986 Information

Description

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19 15.5.4 and 15.10-rc-1 by creating a document with a special crafted documented reference and an XWiki.SchedulerJobClass XObject it is possible to execute arbitrary code on the server whenever an admin visits the scheduler page or the scheduler page is referenced e.g. via an image in a comment on a page in the wiki. The vulnerability has been fixed in XWiki 14.10.19 15.5.5 and 15.9. As a workaround apply the patch manually by modifying the Scheduler.WebHome page.

Reference

https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-37m4-hqxv-w26g https://github.com/xwiki/xwiki-platform/commit/8a92cb4bef7e5f244ae81eed3e64fe9be95827cf https://github.com/xwiki/xwiki-platform/commit/efd3570f3e5e944ec0ad0899bf799bf9563aef87 https://github.com/xwiki/xwiki-platform/commit/f30d9c641750a3f034b5910c6a3a7724ae8f2269 https://jira.xwiki.org/browse/XWIKI-21416

Share on: