Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of service issue via CPU consumption. This vulnerability has been patched in XWiki 14.10.18, 15.5.3 and 15.8 RC1.
Remediation
References
Related Vulnerabilities
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17304)
WordPress Plugin Browser Rejector Remote File Inclusion (2.10)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1484)
WordPress Plugin Usernoise modal feedback/contact form Cross-Site Scripting (3.7.8)