Apache Allura 中通过 Markdown HTML 处理导致的存储型跨站脚本攻击(Stored XSS)。 此问题影响 Apache Allura 1.20.0 及之前版本。 建议用户升级至 1.21.0 版本,该版本已修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Allura | ≤ 1.20.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Allura | 0 ~ 1.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80181 | Apache Allura: Server-side request forgery | |
| CVE-2026-71216 | Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over clearte | |
| CVE-2026-81270 | Apache Allura: Information exposure via search | |
| CVE-2026-85229 | Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CV | |
| CVE-2026-80190 | Apache Allura: Stored XSS via code repositories | |
| CVE-2026-52691 | Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module |
No comments yet