Resource exhaustion in XWiki platform - CVE-2024-21651
Published: January 8, 2024 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the attachment parsing functionality when processing a malformed TAR attachment with manipulated file modification time headers through Tika. A remote attacker can upload a specially crafted TAR file to cause a denial of service.
Exploitation requires the ability to attach a file to a page.