目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1000

100.0%

CVE-2023-37913— XWiki Platform 路径遍历漏洞

CVSS 10.0 · Critical EPSS 3.73% · P88
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-37913 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converter
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prior to versions 14.10.8 and 15.3-rc-1, triggering the office converter with a specially crafted file name allows writing the attachment's content to an attacker-controlled location on the server as long as the Java process has write access to that location. In particular in the combination with attachment moving, a feature introduced in XWiki 14.0, this is easy to reproduce but it also possible to reproduce in versions as old as XWiki 3.5 by uploading the attachment through the REST API which doesn't remove `/` or `\` from the filename. As the mime type of the attachment doesn't matter for the exploitation, this could e.g., be used to replace the `jar`-file of an extension which would allow executing arbitrary Java code and thus impact the confidentiality, integrity and availability of the XWiki installation. This vulnerability has been patched in XWiki 14.10.8 and 15.3RC1. There are no known workarounds apart from disabling the office converter.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
相对路径遍历
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
XWiki Platform 路径遍历漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
XWiki Platform是法国XWiki基金会的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 存在安全漏洞,该漏洞源于使用特制文件名触发 Office 转换器允许将附件的内容写入服务器上攻击者控制的位置,只要 Java 进程对该位置具有写访问权限。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
xwikixwiki-platform >= 3.5-milestone-1, < 14.10.8 -

二、漏洞 CVE-2023-37913 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-37913 的情报信息

登录查看更多情报信息。

同批安全公告 · xwiki · 2023-10-25 · 共 10 条

CVE-2023-3791210.0 CRITICALXWiki Rendering 安全漏洞
CVE-2023-3790910.0 CRITICALXWiki Platform 代码注入漏洞
CVE-2023-451369.7 CRITICALXWiki Platform 跨站脚本漏洞
CVE-2023-451379.1 CRITICALXWiki Platform 安全漏洞
CVE-2023-451359.1 CRITICALXWiki Platform 安全漏洞
CVE-2023-451349.1 CRITICALXWiki Platform 跨站脚本漏洞
CVE-2023-379089.1 CRITICALXWiki Rendering 跨站脚本漏洞
CVE-2023-379108.1 HIGHXWiki Platform 安全漏洞
CVE-2023-379116.5 MEDIUMXWiki Platform 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-37913

暂无评论


发表评论