CVE-2024-36471

HIGH

Apache Allura 1.0.1-1.16.0 - Server-Side Request Forgery via Import Functionality

Title source: llm
STIX 2.1

Description

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allura from 1.0.1 through 1.16.0. Users are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/06/10/1
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/g43164t4bcp0tjwt4opxyks4svm8kvbh

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918 CWE-20 CWE-200
Status published
Products (1)
apache/allura 1.0.1 - 1.17.0
Published Jun 10, 2024
Tracked Since Feb 18, 2026