Apache Allura 中存在未认证的 REST 内容项信息泄露漏洞。 该漏洞影响 Apache Allura 1.19.1 及更早版本。 建议用户升级到修复此问题的 1.20.0 版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Allura | ≤ 1.19.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Allura | 0 ~ 1.19.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78329 | Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter s | |
| CVE-2026-71300 | Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection | |
| CVE-2026-63621 | Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mo | |
| CVE-2026-66908 | Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keys | |
| CVE-2026-66907 | Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the co | |
| CVE-2026-66906 | Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local d | |
| CVE-2026-60093 | Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local d | |
| CVE-2026-59230 | Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel |
No comments yet