org.xwiki.commons:xwiki-commons-classloader-api@18.0.0-rc-1

  • latest version

    18.3.0

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    27 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.xwiki.commons:xwiki-commons-classloader-api package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Relative Path Traversal

    Affected versions of this package are vulnerable to Relative Path Traversal via the resource parameter in the ssx and jsx endpoints when a leading slash is used. An attacker can access sensitive configuration files by crafting a URL that traverses directories.

    Note:

    This issue is due to incomplete fix for CVE-2025-55748.

    How to fix Relative Path Traversal?

    Upgrade org.xwiki.commons:xwiki-commons-classloader-api to version 16.10.17, 17.4.9, 17.10.3, 18.1.0-rc-1 or higher.

    [4.2-milestone-2,16.10.17)[17.0.0-rc-1,17.4.9)[17.5.0,17.10.3)[18.0.0-rc-1,18.1.0-rc-1)