### Impact
One can ask for any file located in the classloader using the template API and a path with “..” in it. For example
“`
{{template name=”../xwiki.hbm.xml”/}}
“`
To our knownledge none of the available files of the classloader in XWiki Standard contain any strong confidential data, hence the low confidentiality value of this advisory.
### Patches
The issue is patched in versions 14.0 and 13.10.3.
### Workarounds
There’s no easy workaround for this issue, administrators should upgrade their wiki.
### References
* https://jira.xwiki.org/browse/XWIKI-19349
* https://github.com/xwiki/xwiki-platform/commit/4917c8f355717bb636d763844528b1fe0f95e8e2
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki](https://jira.xwiki.org)
* Email us at [security mailing list](mailto:[email protected])Read More
References
Back to Main