CVE 5.8 MEDIUM

XWiki PDF export jobs store sensitive cookies unencrypted in job statuses_CVE-2025-58049

5.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store passwords in plain text, and it shouldn't be possible to gain access to plain text passwords by gaining access to, e.g., a backup of the data directory. This vulnerability has been patched in XWiki 16.4.8, 16.10.7, and 17.4.0-rc-1.

Basic Information

ID CVE-2025-58049
Source GitHub_M
Published Aug 28, 2025 at 17:43

Affected Product

Vendor xwiki
Product xwiki-platform
Version >= 14.4.2, < 16.4.8
Affected Versions xwiki xwiki-platform >= 14.4.2, < 16.4.8
xwiki xwiki-platform >= 16.5.0-rc-1, < 16.10.7
xwiki xwiki-platform >= 17.0.0-rc-1, < 17.4.0-rc-1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.