org.xwiki.rendering:xwiki-rendering-xml@5.4.4

  • latest version

    18.7.0

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    23 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.xwiki.rendering:xwiki-rendering-xml package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Eval Injection

    org.xwiki.rendering:xwiki-rendering-xml is a library for the XWiki Rendering Engine

    Affected versions of this package are vulnerable to Eval Injection via the printRaw method in XHTMLWikiPrinter in xwiki-rendering-xml. An attacker can execute arbitrary script macros, including Groovy or Python, by supplying raw rendered content that closes the surrounding {{html}} macro and injects new wiki syntax. This lets a user with edit rights on a document or profile run code with programming rights, leading to remote code execution and unrestricted read/write access to wiki contents. On affected deployments, opening the crafted content as rendered output can expose or corrupt any data the server account can access.

    How to fix Eval Injection?

    Upgrade org.xwiki.rendering:xwiki-rendering-xml to version 14.10.2 or higher.

    [,14.10.2)
    • M
    Cross-site Scripting (XSS)

    org.xwiki.rendering:xwiki-rendering-xml is a library for the XWiki Rendering Engine

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via attributes and link URLs, which can execute scripts when rendered.

    How to fix Cross-site Scripting (XSS)?

    Upgrade org.xwiki.rendering:xwiki-rendering-xml to version 14.6-rc-1 or higher.

    [,14.6-rc-1)