CVE-2023-50069
NixOS vulnerability analysis and mitigation

Overview

WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. The vulnerability was discovered and disclosed on December 19, 2023, and was assigned CVE-2023-50069. The affected component is the recording feature of WireMock with GUI (GitHub Issue).

Technical details

The vulnerability exists due to insufficient validation and sanitization of response bodies in the recording feature. When a test mapping is performed pointing to an attacker's file, the malicious payload is stored and subsequently rendered on the Matched page in the Body area. The CVSS v3.1 base score is 6.1 (MEDIUM) with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (NVD).

Impact

If successfully exploited, this vulnerability allows attackers to execute arbitrary web scripts in the context of the application. The impact is characterized by low confidentiality and integrity impacts, with no impact on availability. The cross-site scripting can potentially lead to unauthorized access to sensitive information or manipulation of the application's functionality (GitHub Issue).

Mitigation and workarounds

Users are advised to follow the official Wiremock documentation to prevent proxying to unintended locations. Additionally, updating to the latest release of Wiremock with GUI is recommended to address this vulnerability (GitHub Issue).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management