Lucene search

K
cve[email protected]CVE-2024-36471
HistoryJun 10, 2024 - 10:15 p.m.

CVE-2024-36471

2024-06-1022:15:11
CWE-918
CWE-200
CWE-20
web.nvd.nist.gov
25
dns rebinding
apache allura
upgrade
disable entry points
security issue

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them.

This issue affects Apache Allura from 1.0.1 through 1.16.0.

Users are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set “disable_entry_points.allura.importers = forge-tracker, forge-discussion” in your .ini config file.

Affected configurations

Vulners
Node
apachealluraRange1.16.0

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache Allura",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "1.16.0",
        "status": "affected",
        "version": "1.0.1",
        "versionType": "semver"
      }
    ]
  }
]

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2024-36471