XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7.
References
Configurations
History
13 Mar 2025, 14:40
Type | Values Removed | Values Added |
---|---|---|
First Time |
Xwiki
Xwiki confluence Migrator |
|
CWE | NVD-CWE-noinfo | |
References | () https://github.com/xwikisas/application-confluence-migrator-pro/commit/6ced42b1f341fd0ce6734fc58c7d694da5f365fb - Patch | |
References | () https://github.com/xwikisas/application-confluence-migrator-pro/security/advisories/GHSA-3w9f-2pph-j5vc - Vendor Advisory | |
Summary |
|
|
CPE | cpe:2.3:a:xwiki:confluence_migrator:*:*:*:*:pro:xwiki:*:* |
07 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-07 17:15
Updated : 2025-03-13 14:40
NVD link : CVE-2025-27604
Mitre link : CVE-2025-27604
CVE.ORG link : CVE-2025-27604
JSON object : View
Products Affected
xwiki
- confluence_migrator
CWE