Advisories for Maven/Org.xwiki.platform/Xwiki-Platform-Tool-Jetty-Resources package

2025

XWiki Jetty Package (XJetty) allows accessing any application file through URL

In an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows accessing files which might contains credentials, like http://myhots/webapps/xwiki/WEB-INF/xwiki.cfg, http://myhots/webapps/xwiki/WEB-INF/xwiki.properties or http://myhots/webapps/xwiki/WEB-INF/hibernate.cfg.xml.