关键信息 漏洞编号: CVE-2024-46911 漏洞名称: Apache Roller: Weakness in CSRF protection allows privilege escalation 发布者: user@roller.apache.org 报告者: David M. Johnson 报告日期: Saturday, October 12, 2024, 5:51:39 AM GMT+8 严重性: important 受影响版本: - Apache Roller 1.0.0 before 6.1.4 描述: - Cross-site Resource Forgery (CSRF) Privilege escalation vulnerability in Apache Roller. - On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF protections allowed an escalation of privileges attack. - This issue affects Apache Roller before 6.1.4. 建议: - Roller users who run multi-blog/user Roller websites are recommended to upgrade to version 6.1.4, which fixes the issue. 发布通知: - Roller 6.1.4 release announcement 信用: - Chi Tran from EEVEE (finder) 参考链接: - https://roller.apache.org/ - https://www.cve.org/CVERecord?id=CVE-2024-46911