原始 OSV JSON{
"id": "GHSA-xq3r-2qv5-vqqm",
"aliases": [
"CVE-2026-23734"
],
"details": "### Impact\n\nIt's possible to get access and read configuration files by using URLs such as `http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false`.\n\nThis can apparently be reproduced on Tomcat instances.\n\n### Patches\n\nThis has been patched in 18.0.0-rc-1, 17.10.3, 17.4.9, 16.10.17.\n\n### Workarounds\n\nThere is no known workaround, other than upgrading XWiki.\n\n### References\n\n* https://jira.xwiki.org/browse/XCOMMONS-3547\n* https://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d672df64429bf\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:[email protected] )\n\n### Attribution\n\nThe vulnerability was reported by Michał Kołek.",
"summary": "XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.2-milestone-2"
},
{
"fixed": "16.10.17"
}
]
}
],
"package": {
"name": "org.xwiki.commons:xwiki-commons-classloader-api",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "17.0.0-rc-1"
},
{
"fixed": "17.4.9"
}
]
}
],
"package": {
"name": "org.xwiki.commons:xwiki-commons-classloader-api",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "17.5.0"
},
{
"fixed": "17.10.3"
}
]
}
],
"package": {
"name": "org.xwiki.commons:xwiki-commons-classloader-api",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "18.0.0-rc-1"
},
{
"fixed": "18.1.0-rc-1"
}
]
}
],
"package": {
"name": "org.xwiki.commons:xwiki-commons-classloader-api",
"ecosystem": "Maven"
}
}
],
"modified": "2026-05-26T17:16:40Z",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
}
],
"published": "2026-05-26T17:16:40Z",
"references": [
{
"url": "https://github.com/xwiki/xwiki-commons/security/advisories/GHSA-xq3r-2qv5-vqqm",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23734",
"type": "ADVISORY"
},
{
"url": "https://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d672df64429bf",
"type": "WEB"
},
{
"url": "https://github.com/xwiki/xwiki-commons",
"type": "PACKAGE"
},
{
"url": "https://jira.xwiki.org/browse/XCOMMONS-3547",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-23"
],
"severity": "CRITICAL",
"github_reviewed": true,
"nvd_published_at": "2026-05-20T20:16:36Z",
"github_reviewed_at": "2026-05-26T17:16:40Z"
}
}