Advisories for Maven/Org.xwiki.platform/Xwiki-Platform-Diff-Xml package


Cookies are sent to external images in rendered diff (and server side request forgery)

XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. These requests are also sent for images from other domains and include all cookies that were sent in the original request to ensure that images with restricted view …