org.xwiki.rendering:xwiki-rendering-transformation-macro@4.2-milestone-1 vulnerabilities

  • latest version

    17.5.0

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    21 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.xwiki.rendering:xwiki-rendering-transformation-macro package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Incorrect Authorization

    Affected versions of this package are vulnerable to Incorrect Authorization via improper handling of the restricted attribute of the transformation context during the processing of nested macros. An attacker can execute arbitrary code with elevated privileges by crafting malicious macro content that bypasses intended restrictions. This is exploitable with any macro that uses the macro content parser with the transform parameter set to true, such as the cache and chart macros that are bundled in XWiki.

    Note: This is only exploitable if an attacker can submit specially crafted macro syntax, e.g., through comments or using the object editor.

    How to fix Incorrect Authorization?

    Upgrade org.xwiki.rendering:xwiki-rendering-transformation-macro to version 13.10.11, 14.4.7, 14.10 or higher.

    [4.2-milestone-1,13.10.11)[14.0,14.4.7)[14.5,14.10)