296,748
Total vulnerabilities in the database
It's possible to get access and read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false.
This can apparently be reproduced on Tomcat instances.
This has been patched in 17.4.0-rc-1, 16.10.7.
There is no known workaround, other than upgrading XWiki.
If you have any questions or comments about this advisory:
The vulnerability was reported by Gregor Neumann.
| Software | From | Fixed in |
|---|---|---|
org.xwiki.platform / xwiki-platform-skin-skinx
|
4.2-milestone-2 | 16.10.7 |