Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Allura: sensitive information exposure via import
Vulnerability Description
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them. Exposing internal files then can lead to other exploits, like session hijacking, or remote code execution. This issue affects Apache Allura from 1.0.1 through 1.15.0. Users are recommended to upgrade to version 1.16.0, which fixes the issue. If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Apache Allura 安全漏洞
Vulnerability Description
Apache Allura是美国阿帕奇(Apache)基金会的一套开源项目托管平台。该平台支持管理源代码存储库、错误报告、维基页面和博客等。 Apache Allura 1.0.1版本至1.15.0版本存在安全漏洞,该漏洞源于不会限制附件中指定的URL值。攻击者利用该漏洞导致会话劫持或远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A