HIGH

CVE-2022-41931

CVSS v3

8.8

HIGH

EPSS Score

18.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrary Groovy, Python or Velocity code in XWiki due to improper neutralization of the macro parameters of the icon picker macro. The problem has been patched in XWiki 13.10.7, 14.5 and 14.4.2. Workarounds: The [patch](https://github.com/xwiki/xwiki-platform/commit/47eb8a5fba550f477944eb6da8ca91b87eaf1d01) can be manually applied by editing `IconThemesCode.IconPickerMacro` in the object editor. The whole document can also be replaced by the current version by importing the document from the XAR archive of a fixed version as the only changes to the document have been security fixes and small formatting changes.

Technical details

Published
11/23/2022

Frequently asked questions

What is CVE-2022-41931?

xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrary Groovy, Python or Velocity code in XWiki due to improper neutralization of the macro parameters of the icon picker macro. The problem has been patched in XWiki 13.10.7, 14.5 and 14.4.2. Workarounds: The [patch](https://github.com/xwiki/xwiki-platform/commit/47eb8a5fba550f477944eb6da8ca91b87eaf1d01) can be manually applied by editing `IconThemesCode.IconPickerMacro` in the object editor. The whole document can also be replaced by the current version by importing the document from the XAR archive of a fixed version as the only changes to the document have been security fixes and small formatting changes.

Is CVE-2022-41931 actively exploited?

Active exploitation of CVE-2022-41931 has not been confirmed. The EPSS score is 18.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-41931?

CVE-2022-41931 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-41931 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.