SCA: security update for org.xwiki.platform:xwiki-core-rendering-macro-footnotes, org.xwiki.rendering:xwiki-rendering-macro-footnotes (GHSA-35j5-m29r-xfq5)

high Tenable Self-Hosted Container Security Plugin ID 409303

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another
syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and
`org.xwiki.platform:xwiki-rendering-macro-footnotes` and prior to version 15.1-rc-1 of
`org.xwiki.platform:xwiki-rendering-macro-footnotes`, the footnote macro executed its content in a
potentially different context than the one in which it was defined. In particular in combination with the
include macro, this allows privilege escalation from a simple user account in XWiki to programming rights
and thus remote code execution, impacting the confidentiality, integrity and availability of the whole
XWiki installation. This vulnerability has been patched in XWiki 14.10.6 and 15.1-rc-1. There is no
workaround apart from upgrading to a fixed version of the footnote macro. (CVE-2023-37912)

See Also

https://github.com/advisories/GHSA-35j5-m29r-xfq5

Plugin Details

Severity: High

ID: 409303

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-37912

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/25/2023

Vulnerability Publication Date: 10/25/2023

Reference Information

CVE: CVE-2023-37912

cwe: CWE-270