CVE-2023-37912

XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and `org.xwiki.platform:xwiki-rendering-macro-footnotes` and prior to version 15.1-rc-1 of `org.xwiki.platform:xwiki-rendering-macro-footnotes`, the footnote macro executed its content in a potentially different context than the one in which it was defined. In particular in combination with the include macro, this allows privilege escalation from a simple user account in XWiki to programming rights and thus remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.6 and 15.1-rc-1. There is no workaround apart from upgrading to a fixed version of the footnote macro.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xwiki:xwiki-rendering:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki-rendering:15.0:rc1:*:*:*:*:*:*

History

21 Nov 2024, 08:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.9
References () https://github.com/xwiki/xwiki-rendering/commit/5f558b8fac8b716d19999225f38cb8ed0814116e - Patch () https://github.com/xwiki/xwiki-rendering/commit/5f558b8fac8b716d19999225f38cb8ed0814116e - Patch
References () https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-35j5-m29r-xfq5 - Patch, Vendor Advisory () https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-35j5-m29r-xfq5 - Patch, Vendor Advisory
References () https://jira.xwiki.org/browse/XRENDERING-688 - Exploit, Issue Tracking, Patch, Vendor Advisory () https://jira.xwiki.org/browse/XRENDERING-688 - Exploit, Issue Tracking, Patch, Vendor Advisory

31 Oct 2023, 18:48

Type Values Removed Values Added
References (MISC) https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-35j5-m29r-xfq5 - (MISC) https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-35j5-m29r-xfq5 - Patch, Vendor Advisory
References (MISC) https://jira.xwiki.org/browse/XRENDERING-688 - (MISC) https://jira.xwiki.org/browse/XRENDERING-688 - Exploit, Issue Tracking, Patch, Vendor Advisory
References (MISC) https://github.com/xwiki/xwiki-rendering/commit/5f558b8fac8b716d19999225f38cb8ed0814116e - (MISC) https://github.com/xwiki/xwiki-rendering/commit/5f558b8fac8b716d19999225f38cb8ed0814116e - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:xwiki:xwiki-rendering:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki-rendering:15.0:rc1:*:*:*:*:*:*
First Time Xwiki
Xwiki xwiki-rendering
CWE NVD-CWE-noinfo

25 Oct 2023, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-25 18:17

Updated : 2024-11-21 08:12


NVD link : CVE-2023-37912

Mitre link : CVE-2023-37912

CVE.ORG link : CVE-2023-37912


JSON object : View

Products Affected

xwiki

  • xwiki-rendering
CWE
CWE-270

Privilege Context Switching Error

NVD-CWE-noinfo