XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:`). It was also possible to bypass it when using URL such as `http:/mydomain.com`. The problem has been patched on XWiki 13.10.10, 14.4.4 and 14.8RC1.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/e4f7f68e93cb08c25632c126356d218abf192d1e#diff-c445f288d5d63424f56ef13f65514ab4e174a72e979b53b88197c2b7def267cf | Patch | 
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-xwph-x6xj-wggv | Exploit Patch Vendor Advisory | 
| https://jira.xwiki.org/browse/XWIKI-10309 | Exploit Issue Tracking | 
| https://jira.xwiki.org/browse/XWIKI-19994 | Exploit Issue Tracking | 
| https://github.com/xwiki/xwiki-platform/commit/e4f7f68e93cb08c25632c126356d218abf192d1e#diff-c445f288d5d63424f56ef13f65514ab4e174a72e979b53b88197c2b7def267cf | Patch | 
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-xwph-x6xj-wggv | Exploit Patch Vendor Advisory | 
| https://jira.xwiki.org/browse/XWIKI-10309 | Exploit Issue Tracking | 
| https://jira.xwiki.org/browse/XWIKI-19994 | Exploit Issue Tracking | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 07:56
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.7 | 
| References | () https://github.com/xwiki/xwiki-platform/commit/e4f7f68e93cb08c25632c126356d218abf192d1e#diff-c445f288d5d63424f56ef13f65514ab4e174a72e979b53b88197c2b7def267cf - Patch | |
| References | () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-xwph-x6xj-wggv - Exploit, Patch, Vendor Advisory | |
| References | () https://jira.xwiki.org/browse/XWIKI-10309 - Exploit, Issue Tracking | |
| References | () https://jira.xwiki.org/browse/XWIKI-19994 - Exploit, Issue Tracking | 
26 Apr 2023, 18:30
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:xwiki:xwiki:6.0:rc1:*:*:*:*:*:* cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
| References | (MISC) https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-xwph-x6xj-wggv - Exploit, Patch, Vendor Advisory | |
| References | (MISC) https://jira.xwiki.org/browse/XWIKI-10309 - Exploit, Issue Tracking | |
| References | (MISC) https://jira.xwiki.org/browse/XWIKI-19994 - Exploit, Issue Tracking | |
| References | (MISC) https://github.com/xwiki/xwiki-platform/commit/e4f7f68e93cb08c25632c126356d218abf192d1e#diff-c445f288d5d63424f56ef13f65514ab4e174a72e979b53b88197c2b7def267cf - Patch | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.1 | 
| First Time | Xwiki xwiki Xwiki | 
15 Apr 2023, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-04-15 16:15
Updated : 2024-11-21 07:56
NVD link : CVE-2023-29204
Mitre link : CVE-2023-29204
CVE.ORG link : CVE-2023-29204
JSON object : View
Products Affected
                xwiki
- xwiki
CWE
                
                    
                        
                        CWE-601
                        
            URL Redirection to Untrusted Site ('Open Redirect')
