-
CVSS Score
-The vulnerability stemmed from missing access checks and template validation in key actions (login, register, skin). The patches explicitly added checks for view rights (XWiki.java) and disallowed non-default templates in affected actions (LoginAction, RegisterAction, etc.). The functions modified in the commit correspond directly to the attack vectors described in the advisory (bypass via 'xpage' parameter and improper document loading). High confidence is justified as the commit diffs and CVE details explicitly address these points.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.xwiki.platform:xwiki-platform-oldcore | maven | < 13.10.4 | 13.10.4 |
| org.xwiki.platform:xwiki-platform-oldcore | maven | >= 14.0, < 14.2 | 14.2 |
A Semantic Attack on Google Gemini - Read the Latest Research