Apache

Allura

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 04.09.2026 07:06:19
  • Zuletzt bearbeitet 08.09.2026 14:00:01

Apache Allura: stored XSS via SVN code repositories.  Git repositories are not known to be affected.  The vulnerability is likely mitigated via default CSP headers. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgr...

  • EPSS 0.39%
  • Veröffentlicht 04.09.2026 06:59:49
  • Zuletzt bearbeitet 08.09.2026 14:00:01

Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

  • EPSS 0.21%
  • Veröffentlicht 04.09.2026 06:52:42
  • Zuletzt bearbeitet 08.09.2026 19:19:53

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

  • EPSS 0.2%
  • Veröffentlicht 04.09.2026 06:50:14
  • Zuletzt bearbeitet 08.09.2026 14:00:01

Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

  • EPSS 0.23%
  • Veröffentlicht 24.08.2026 16:42:20
  • Zuletzt bearbeitet 28.08.2026 17:54:22

Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue.

  • EPSS 0.43%
  • Veröffentlicht 12.08.2026 16:42:27
  • Zuletzt bearbeitet 17.08.2026 19:10:03

XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

  • EPSS 0.43%
  • Veröffentlicht 12.08.2026 16:41:58
  • Zuletzt bearbeitet 17.08.2026 19:09:53

XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

  • EPSS 0.34%
  • Veröffentlicht 12.08.2026 16:41:41
  • Zuletzt bearbeitet 17.08.2026 19:09:42

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

  • EPSS 0.54%
  • Veröffentlicht 12.08.2026 16:41:19
  • Zuletzt bearbeitet 17.08.2026 19:08:51

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

  • EPSS 0.73%
  • Veröffentlicht 11.08.2026 17:03:04
  • Zuletzt bearbeitet 17.08.2026 19:09:32

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.