SB2025032539 - Multiple vulnerabilities in XWiki platform
Published: March 25, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper privilege management (CVE-ID: CVE-2025-29924)
The vulnerability allows a remote attacker to gain acces to sensitive information on the system.
The vulnerability exists due to wrong wiki reference used in AuthorizationManager. A remote attacker can gain access to private information.
2) Transmission of Private Resources into a New Sphere ('Resource Leak') (CVE-ID: CVE-2025-29925)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the resource leak issue. A remote attacker can access private pages information through REST endpoint.
Remediation
Install update from vendor's website.
References
- https://github.com/xwiki/xwiki-platform/commit/5f98bde87288326cf5787604e2bb87836875ed0e
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-gq32-758c-3wm3
- https://jira.xwiki.org/browse/XWIKI-22640
- https://github.com/xwiki/xwiki-platform/commit/1fb12d2780f37b34a1b4dfdf8457d97ce5cbb2df
- https://github.com/xwiki/xwiki-platform/commit/bca72f5ce971a31dba2a016d8dd8badda4475206
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-22q5-9phm-744v
- https://jira.xwiki.org/browse/XWIKI-22630
- https://jira.xwiki.org/browse/XWIKI-22639