CVE-2023-29204

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
15/04/2023
Last modified:
26/04/2023

Description

XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:`). It was also possible to bypass it when using URL such as `http:/mydomain.com`. The problem has been patched on XWiki 13.10.10, 14.4.4 and 14.8RC1.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 6.0 (including) 13.10.10 (excluding)
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 14.4.0 (including) 14.4.4 (excluding)
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 14.5 (including) 14.7 (including)
cpe:2.3:a:xwiki:xwiki:6.0:rc1:*:*:*:*:*:*