CVE-2022-23620
Path traversal in xwiki-platform-skin-skinx
6.8
MEDIUM
CVSS 3.1
EPSS 0.96%
描述
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. AbstractSxExportURLFactoryActionHandler#processSx does not escape anything from SSX document reference when serializing it on filesystem, so it's easy to mess up the HTML export process with reference elements containing filesystem syntax like "../", "./". or "/" in general (the last two not causing any security threat, but can cause conflicts with others serialized files). Patch can be found in 13.6-rc-1. Giving script or subwiki admin right only to trusted people and disabling HTML/PDF export can be done as workaround.
如何修補 CVE-2022-23620
要修補 CVE-2022-23620,請將受影響套件升級到下列已修補版本。
- —升級至 13.6 或更新版本
CVE-2022-23620 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 6.2-rc-1, < 13.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.8 | CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:H |