CVE-2025-55748: XWiki configuration files can be accessed through jsx and sx endpoints
It’s possible to get access and read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false
.
This can apparently be reproduced on Tomcat instances.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-55748 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →