SB2024010844 - Multiple vulnerabilities in XWiki platform
Published: January 8, 2024 Updated: May 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2024-21651)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the attachment parsing functionality when processing a malformed TAR attachment with manipulated file modification time headers through Tika. A remote attacker can upload a specially crafted TAR file to cause a denial of service.
Exploitation requires the ability to attach a file to a page.
2) Eval Injection (CVE-ID: CVE-2024-21650)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the user registration feature when processing user-supplied "first name" or "last name" fields during registration. A remote attacker can submit crafted registration data to execute arbitrary code.
Only installations that have user registration enabled for guests are vulnerable.
3) Improper Handling of Insufficient Privileges (CVE-ID: CVE-2024-21648)
The vulnerability allows a remote user to gain rights they do not have anymore.
The vulnerability exists due to improper handling of insufficient privileges in the rollback action when performing a page rollback. A remote user can roll back a page to a previous version to gain rights they do not have anymore.
User interaction is required.
Remediation
Install update from vendor's website.
References
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-8959-rfxh-r4j4
- https://jira.xwiki.org/browse/XCOMMONS-2796
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rj7p-xjv7-7229
- https://github.com/xwiki/xwiki-platform/commit/b290bfd573c6f7db6cc15a88dd4111d9fcad0d31
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-xh35-w7wg-95v3
- https://github.com/xwiki/xwiki-platform/commit/4de72875ca49602796165412741033bfdbf1e680