Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of service issue via CPU consumption. This vulnerability has been patched in XWiki 14.10.18, 15.5.3 and 15.8 RC1.
Remediation
References
Related Vulnerabilities
Django Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0473)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-1102)
Apache Tomcat Other Vulnerability (CVE-2007-1858)
WordPress Plugin Favicon by RealFaviconGenerator Unspecified Vulnerability (1.2.13)