← Back

CVE-2022-41931

nvd nist
Published: Nov 23, 2022Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrary Groovy, Python or Velocity code in XWiki due to improper neutralization of the macro parameters of the icon picker macro. The problem has been patched in XWiki 13.10.7, 14.5 and 14.4.2. Workarounds: The [patch](https://github.com/xwiki/xwiki-platform/commit/47eb8a5fba550f477944eb6da8ca91b87eaf1d01) can be manually applied by editing `IconThemesCode.IconPickerMacro` in the object editor. The whole document can also be replaced by the current version by importing the document from the XAR archive of a fixed version as the only changes to the document have been security fixes and small formatting changes.

Affected (6)

Products: Xwiki: Xwiki
1 product
Xwiki
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Xwiki
After 6.4 to 13.10.7
From 14.0.0 to 14.4.2
Version 14.4.3
Version 14.4.4
Version 6.4 milestone2
Version 6.4 milestone3

References (6)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
ExploitPatchThird Party Advisory
Source: security-advisories@github.com
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory

Timeline

No history available yet.