{"id":"GHSA-9j36-3cp4-rh4j","summary":"XWiki vulnerable to Code Injection in template provider administration","details":"### Impact\n\nAny user with edit rights on any document (e.g., the own user profile) can execute code with programming rights, leading to remote code execution by following these steps:\n\n1. Set the title of any document you can edit (can be the user profile) to\n```\n    {{async async=\"true\" cached=\"false\" context=\"doc.reference\"}}{{groovy}}println(\"Hello \" + \"from groovy!\"){{/groovy}}{{/async}}\n```\n2. Use the object editor to add an object of type `XWiki.TemplateProviderClass` (named \"Template Provider Class\") to that document.\n3. Go to another document you can view (can be the home page) and append `?sheet=XWiki.AdminTemplatesSheet` to the URL.\n\nWhen the attack is successful, a template with name \"Hello from groovy!\" is displayed in the list while on fixed systems, the full title should be displayed.\n\n### Patches\n\nThis vulnerability has been patched in XWiki 13.10.11, 14.4.8, 14.10.1 and 15.0 RC1.\n\n### Workarounds\n\nThe vulnerability can be fixed by patching the code in the affected XWiki document as shown in the [patch](https://github.com/xwiki/xwiki-platform/commit/7bf7094f8ffac095f5d66809af7554c9cc44de09).\n\n### References\n\n* https://jira.xwiki.org/browse/XWIKI-20268\n* https://github.com/xwiki/xwiki-platform/commit/7bf7094f8ffac095f5d66809af7554c9cc44de09\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)","aliases":["CVE-2023-29514"],"modified":"2023-11-08T04:12:19.774698Z","published":"2023-04-20T21:46:57Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-04-20T21:46:57Z","nvd_published_at":"2023-04-19T00:15:08Z","cwe_ids":["CWE-74"]},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9j36-3cp4-rh4j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29514"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/7bf7094f8ffac095f5d66809af7554c9cc44de09"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20268"}],"affected":[{"package":{"name":"org.xwiki.platform.applications:xwiki-application-administration","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform.applications/xwiki-application-administration"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.35"},{"last_affected":"1.49"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-9j36-3cp4-rh4j/GHSA-9j36-3cp4-rh4j.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-administration","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-administration"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1-milestone-1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c 4.2-milestone-1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-9j36-3cp4-rh4j/GHSA-9j36-3cp4-rh4j.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-administration-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-administration-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2-milestone-1"},{"fixed":"13.10.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-9j36-3cp4-rh4j/GHSA-9j36-3cp4-rh4j.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-administration-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-administration-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0-rc-1"},{"fixed":"14.4.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-9j36-3cp4-rh4j/GHSA-9j36-3cp4-rh4j.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-administration-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-administration-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.5"},{"fixed":"14.10.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-9j36-3cp4-rh4j/GHSA-9j36-3cp4-rh4j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}