CVE 8.7 HIGH

The XWiki Jetty package (XJetty) allows accessing any application file through URL_CVE-2025-55749

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows accessing files which might contains credentials. Fixed in 16.10.11, 17.4.4, and 17.7.0.

AI Analysis

XWiki Jetty package vulnerability allows accessing application files through URL

Basic Information

ID CVE-2025-55749
Source GitHub_M
Published Dec 1, 2025 at 20:09
Modified Dec 1, 2025 at 20:34

Affected Product

Vendor xwiki
Product xwiki-platform
Version >= 16.7.0, < 16.10.11
Affected Versions xwiki xwiki-platform >= 16.7.0, < 16.10.11
xwiki xwiki-platform >= 17.0.0-rc1, < 17.4.4
xwiki xwiki-platform >= 17.5.0, < 17.7.0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor XWiki
Product XWiki Jetty package (XJetty)
Version 16.7.0 to 16.10.11, 17.0.0-rc1 to 17.4.4, 17.5.0 to 17.7.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.