17.5.0
13 years ago
21 days ago
Known vulnerabilities in the org.xwiki.rendering:xwiki-rendering-transformation-macro package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Incorrect Authorization via improper handling of the restricted attribute of the transformation context during the processing of nested macros. An attacker can execute arbitrary code with elevated privileges by crafting malicious macro content that bypasses intended restrictions. This is exploitable with any macro that uses the macro content parser with the Note: This is only exploitable if an attacker can submit specially crafted macro syntax, e.g., through comments or using the object editor. How to fix Incorrect Authorization? Upgrade | [4.2-milestone-1,13.10.11)[14.0,14.4.7)[14.5,14.10) |