Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-rp38-24m3-rx87: The lesscss script service allows cache clearing without programming right

Impact

The script API of the LESS compiler in XWiki is incorrectly checking for rights when calling the cache cleaning API, making it possible to clean the cache without having programming right. The only impact of this is a slowdown in XWiki execution as the caches are re-filled. As this vulnerability requires script right to exploit, and script right already allows unlimited execution of scripts, the additional impact due to this vulnerability is low.

Patches

This has been patched in XWiki 15.10.12, 16.4.3 and 16.8.0 RC1.

Workarounds

We’re not aware of any workaround except for being careful whom to give script right, which is a general recommendation.

ghsa
#vulnerability#git#java#jira#maven
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-32972

The lesscss script service allows cache clearing without programming right

Low severity GitHub Reviewed Published Apr 29, 2025 in xwiki/xwiki-platform • Updated Apr 29, 2025

Package

maven org.xwiki.platform:xwiki-platform-lesscss-script (Maven)

Affected versions

>= 6.1-milestone-1, < 15.10.12

>= 16.0.0-rc-1, < 16.4.3

>= 16.5.0-rc-1, < 16.8.0-rc-1

Patched versions

15.10.12

16.4.3

16.8.0-rc-1

Impact

The script API of the LESS compiler in XWiki is incorrectly checking for rights when calling the cache cleaning API, making it possible to clean the cache without having programming right. The only impact of this is a slowdown in XWiki execution as the caches are re-filled. As this vulnerability requires script right to exploit, and script right already allows unlimited execution of scripts, the additional impact due to this vulnerability is low.

Patches

This has been patched in XWiki 15.10.12, 16.4.3 and 16.8.0 RC1.

Workarounds

We’re not aware of any workaround except for being careful whom to give script right, which is a general recommendation.

References

  • GHSA-rp38-24m3-rx87
  • xwiki/xwiki-platform@9175212
  • https://jira.xwiki.org/browse/XWIKI-22462

Published to the GitHub Advisory Database

Apr 29, 2025

Last updated

Apr 29, 2025

ghsa: Latest News

GHSA-9fwj-9mjf-rhj3: laravel-auth0 SDK Vulnerable to Brute Force Authentication Tags of CookieStore Sessions