CVE-2024-21651: XWiki

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of service issue via CPU consumption. This vulnerability has been patched in XWiki 14.10.18, 15.5.3 and 15.8 RC1.

Affected products

  • XWiki XWiki: from 14.10, before 14.10.18 (fixed in 14.10.18); from 15.5, before 15.5.3 (fixed in 15.5.3); from 15.6, before 15.8 (fixed in 15.8)

Published 2024-01-09. Last modified 2026-06-17.