CVE-2023-26479
Last modified
CVE-2023-26479 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well by the parser. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well by the parser. As a consequence, some pages becomes unusable, including the user index (if the page containing the faulty content is a user page) and the page index. Note that on the page, the normal UI is completely missing and it is not possible to open the editor directly to revert the change as the stack overflow is already triggered while getting the title of the document. This means that it is quite difficult to remove this content once inserted. This has been patched in XWiki 13.10.10, 14.4.6, and 14.9-rc-1. A temporary workaround to avoid Stack Overflow errors is to increase the memory allocated to the stack by using the `-Xss` JVM parameter (e.g., `-Xss32m`). This should allow the parser to pass and to fix the faulty content. The consequences for other aspects of the system (e.g., performance) are unknown, and this workaround should be only be used as a temporary solution. The workaround does not prevent the issue occurring again with other content. Consequently, it is strongly advised to upgrade to a version where the issue has been patched.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Xwiki | >= 6.0, < 13.10.10 |
| Xwiki | Xwiki | >= 14.0, < 14.4.6 |
| Xwiki | Xwiki | >= 14.5, < 14.9 |
References
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-52vf-hvv3-98h7Exploit, Vendor Advisory
- https://jira.xwiki.org/browse/XWIKI-19838Exploit, Issue Tracking, Vendor Advisory
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-52vf-hvv3-98h7Exploit, Vendor Advisory
- https://jira.xwiki.org/browse/XWIKI-19838Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-26479?
How severe is CVE-2023-26479?
How do I fix CVE-2023-26479?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-26473XWiki Platform is a generic wiki platform. Starting in versi…6.5
- CVE-2023-26474XWiki Platform is a generic wiki platform. Starting in versi…8.8
- CVE-2023-26475XWiki Platform is a generic wiki platform. Starting in versi…8.8
- CVE-2023-26476XWiki Platform is a generic wiki platform. Starting in versi…7.5
- CVE-2023-26477XWiki Platform is a generic wiki platform. Starting in versi…9.8
- CVE-2023-26478XWiki Platform is a generic wiki platform. Starting in versi…8.1
- CVE-2023-2648A vulnerability was found in Weaver E-Office 9.5. It has bee…9.8
- CVE-2023-26480XWiki Platform is a generic wiki platform. Starting in versi…5.4
- CVE-2023-26481authentik is an open-source Identity Provider. Due to an ins…6.5
- CVE-2023-26482Nextcloud server is an open source home cloud implementation…8.8
- CVE-2023-26483gosaml2 is a Pure Go implementation of SAML 2.0. SAML Servic…5.3
- CVE-2023-26484KubeVirt is a virtual machine management add-on for Kubernet…8.2
Are you affected by CVE-2023-26479?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
