Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <5ba6465f-0850-e097-dda4-33a2fffb9efd@apache.org>
Date: Fri, 21 Jun 2024 17:49:12 +0000
From: David Philip Brondsema <brondsem@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2024-38379: Apache Allura: Stored authenticated XSS 

Severity: moderate

Affected versions:

- Apache Allura 1.4.0 through 1.17.0

Description:

Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted.

This issue affects Apache Allura: from 1.4.0 through 1.17.0.

Users are recommended to upgrade to version 1.17.1, which fixes the issue.

Credit:

Ömer "WASP" Akincir  (finder)

References:

https://allura.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-38379

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.