{"id":"CVE-2025-55749","summary":"The XWiki Jetty package (XJetty) allows accessing any application file through URL","details":"XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows accessing files which might contains credentials. Fixed in 16.10.11, 17.4.4, and 17.7.0.","aliases":["GHSA-53gx-j3p6-2rw9"],"modified":"2026-08-12T03:51:12.755642906Z","published":"2025-12-01T20:09:46.410Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-284"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55749.json"},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/compare/8b68d8a70b43f25391b3ee48477d7eb71b95cf4b...99a04a0e2143583f5154a43e02174155da7e8e10"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-23438"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55749.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-53gx-j3p6-2rw9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55749"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/42fb063749dd88cc78196f72d7318b7179285ebd"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/99a04a0e2143583f5154a43e02174155da7e8e10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xwiki/xwiki-commons","events":[{"introduced":"5d810c17daacfef0a76e0800354511dbdf871b5b"},{"fixed":"29b891e1b819314bd49b15c3a3af4e5fc1c4d4a4"},{"introduced":"e84d9bd1b4c0c8219597e10acfd8fbd692416294"},{"fixed":"50106b5a61b44a51751052838369b7d1925f5dd0"},{"introduced":"0f12307c8803e5abd5fe7016bd0adf0850c5f903"},{"fixed":"8bea8edcf83c419136ddc1a965ccfa03ffdf7c2a"}],"database_specific":{"extracted_events":[{"introduced":"16.7.0"},{"fixed":"16.10.11"},{"introduced":"17.0.0"},{"fixed":"17.4.4"},{"introduced":"17.5.0"},{"fixed":"17.7.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*"}},{"type":"GIT","repo":"https://github.com/xwiki/xwiki-platform","events":[{"introduced":"a1474519e8b8025cd704b608450b7622d3163681"},{"fixed":"917882dec98bf180d91c04274e97aafbcfbdbb85"},{"introduced":"7edb5b7d98170ec081c7e30237971d7dfb8a4401"},{"fixed":"b2aaf43ce9d0ed5ac7e3882b870fb730cf0d84e4"},{"introduced":"b85d21efede0f7c07c04c5ad5fb7610be0866096"},{"fixed":"03c1fa2f2da0c9bebf2ce25de8c11189b7e40cc7"},{"fixed":"42fb063749dd88cc78196f72d7318b7179285ebd"},{"fixed":"99a04a0e2143583f5154a43e02174155da7e8e10"}],"database_specific":{"extracted_events":[{"introduced":"16.7.0"},{"fixed":"16.10.11"},{"introduced":"17.0.0"},{"fixed":"17.4.4"},{"introduced":"17.5.0"},{"fixed":"17.7.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55749.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}