Apache Allura:通过 SVN 代码仓库存在存储型跨站脚本(XSS)漏洞。Git 仓库据信不受影响。该漏洞很可能已通过默认的 CSP(内容安全策略)请求头得到缓解。 此问题影响 Apache Allura 1.20.0 及更早版本。 建议用户升级到 1.21.0 版本以修复该问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Allura | ≤ 1.20.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Allura | 0 ~ 1.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80180 | Apache Allura: Stored XSS via markdown HTML processing | |
| CVE-2026-80181 | Apache Allura: Server-side request forgery | |
| CVE-2026-71216 | Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over clearte | |
| CVE-2026-81270 | Apache Allura: Information exposure via search | |
| CVE-2026-85229 | Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CV | |
| CVE-2026-52691 | Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module |
No comments yet