XWiki configuration files can be accessed through jsx and sx endpoints
Critical severity
GitHub Reviewed
Published
Sep 3, 2025
in
xwiki/xwiki-platform
•
Updated Sep 3, 2025
Package
Affected versions
>= 4.2-milestone-2, < 16.10.7
Patched versions
16.10.7
Description
Published to the GitHub Advisory Database
Sep 3, 2025
Reviewed
Sep 3, 2025
Last updated
Sep 3, 2025
Impact
It's possible to get access and read configuration files by using URLs such as
http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false
.This can apparently be reproduced on Tomcat instances.
Patches
This has been patched in 17.4.0-rc-1, 16.10.7.
Workarounds
There is no known workaround, other than upgrading XWiki.
For more information
If you have any questions or comments about this advisory:
Attribution
The vulnerability was reported by Gregor Neumann.
References