Apache Allura 的 Webhooks 功能存在服务器端请求伪造(SSRF)漏洞。 该漏洞影响 Apache Allura 1.20.0 及更早版本。 建议用户升级至 1.21.0 或更高版本,该版本已修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Allura | ≤ 1.20.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Allura | 0 ~ 1.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80180 | Apache Allura: Stored XSS via markdown HTML processing | |
| CVE-2026-71216 | Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over clearte | |
| CVE-2026-81270 | Apache Allura: Information exposure via search | |
| CVE-2026-85229 | Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CV | |
| CVE-2026-80190 | Apache Allura: Stored XSS via code repositories | |
| CVE-2026-52691 | Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module |
No comments yet