漏洞关键信息 标题 Remote code execution using the confluence details summary macro 引用 GHSA-472x-fwh9-r82f 严重性 Severity: High 8.3 / 10 包名 Package: com.xwiki.pro:xwiki-pro-macros-confluence-bridges-ui 影响版本 Affected versions: <= 1.27.0 补丁版本 Patched versions: 1.27.1 描述 The macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. 概述 (POC) 1. As a user without programming rights, create a new page and add a details macro to it with an async macro call and some groovy code. 2. Save the page. 3. Using an admin account, add the detailssummary macro to another page and ensure it includes the correct CQL parameter so that the previously created page is included. CVSS v3 基本指标 Attack vector: Network Attack complexity: Low Privileges required: Low User interaction: None Scope: Unchanged Confidentiality: High Integrity: High Availability: Low CWE ID No CWEs CVE ID CVE-2025-65036