Storing Passwords in a Recoverable Format Affecting org.xwiki.platform:xwiki-platform-export-pdf-api package, versions [,16.4.8)[16.5.0-rc-1,16.10.7)[17.0.0-rc-1,17.4.0-rc-1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGXWIKIPLATFORM-12234207
  • published29 Aug 2025
  • disclosed28 Aug 2025
  • creditMichael Hamann

Introduced: 28 Aug 2025

NewCVE-2025-58049  (opens in a new tab)
CWE-212  (opens in a new tab)
CWE-257  (opens in a new tab)

How to fix?

Upgrade org.xwiki.platform:xwiki-platform-export-pdf-api to version 16.4.8, 16.10.7, 17.4.0-rc-1 or higher.

Overview

org.xwiki.platform:xwiki-platform-export-pdf-api is an API for multipage PDF export that supports both client-side printing, using the user's web browser, and server-side printing, e.g. using a headless Chrome browser that may run inside a Docker container.

Affected versions of this package are vulnerable to Storing Passwords in a Recoverable Format via the PDF export job process. An attacker can obtain sensitive user credentials by accessing the serialized job status files stored in the permanent directory, as these files contain unencrypted cookies and the encryption key is also present in the same directory.

CVSS Base Scores

version 4.0
version 3.1