Skip to content

RCE in XWiki

High severity GitHub Reviewed Published Oct 15, 2020 in xwiki/xwiki-platform • Updated Feb 1, 2023

Package

maven org.xwiki.platform:xwiki-platform-oldcore (Maven)

Affected versions

< 11.10.6
>= 12.0, < 12.5

Patched versions

11.10.6
12.5

Description

Impact

Any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code execution.

Patches

It has been patched in both version XWiki 12.5 and XWiki 11.10.6.

Workarounds

The only workaround is to give SCRIPT right only to trusted users.

References

https://jira.xwiki.org/browse/XWIKI-17423

It's been reported by the GitHub Security Lab under https://jira.xwiki.org/browse/XWIKI-17141.

For more information

If you have any questions or comments about this advisory:

References

@tmortagne tmortagne published to xwiki/xwiki-platform Oct 15, 2020
Reviewed Oct 16, 2020
Published to the GitHub Advisory Database Oct 16, 2020
Published by the National Vulnerability Database Oct 16, 2020
Last updated Feb 1, 2023

Severity

High
8.6
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE ID

CVE-2020-15252

GHSA ID

GHSA-5hv6-mh8q-q9v8

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.