GHSA-9jq5-xwqw-q8j3
Dashboard / Vulnerabilities / GHSA-9jq5-xwqw-q8j3
Summary: XWiki Platform vulnerable to page render failure due to broken translations
Details: ### Impact It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. ### Patches The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. ### Workarounds There is no other workaround other than fixing any way to create a document that fail to load. ### References https://jira.xwiki.org/browse/XWIKI-20460 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki.org](https://jira.xwiki.org/) * Email us at [Security Mailing List](mailto:[email protected])
References: https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9jq5-xwqw-q8j3, https://nvd.nist.gov/vuln/detail/CVE-2023-29520, https://github.com/xwiki/xwiki-platform, https://jira.xwiki.org/browse/XWIKI-20460
Affected packages
Package
Name: org.xwiki.platform:xwiki-platform-localization-source-wiki
Purl: pkg:maven/org.xwiki.platform/xwiki-platform-localization-source-wiki
Affected ranges
Type: ECOSYSTEM
Events:
