Loading HuntDB...

GHSA-9jq5-xwqw-q8j3

GitHub Security Advisory

XWiki Platform vulnerable to page render failure due to broken translations

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact

It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object.

### Patches

The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.

### Workarounds

There is no other workaround other than fixing any way to create a document that fail to load.

### References

https://jira.xwiki.org/browse/XWIKI-20460

### For more information

If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:[email protected])

Affected Packages

Maven org.xwiki.platform:xwiki-platform-localization-source-wiki
Affected versions: 4.3-milestone-2 (fixed in 13.10.11)
Maven org.xwiki.platform:xwiki-platform-localization-source-wiki
Affected versions: 14.0-rc-1 (fixed in 14.4.8)
Maven org.xwiki.platform:xwiki-platform-localization-source-wiki
Affected versions: 14.5 (fixed in 14.10.1)

Related CVEs

Key Information

GHSA ID
GHSA-9jq5-xwqw-q8j3
Published
April 20, 2023 10:05 PM
Last Modified
April 20, 2023 10:05 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.xwiki.platform:xwiki-platform-localization-source-wiki
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.