40 lines
1.3 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-36471",
"sourceIdentifier": "security@apache.org",
"published": "2024-06-10T22:15:11.893",
"lastModified": "2024-06-10T22:15:11.893",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.\u00a0 Project administrators can run these imports, which could cause Allura to read from internal services and expose them.\n\nThis issue affects Apache Allura from 1.0.1 through 1.16.0.\n\nUsers are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set \"disable_entry_points.allura.importers = forge-tracker, forge-discussion\" in your .ini config file.\n\n"
}
],
"metrics": {},
"weaknesses": [
{
"source": "security@apache.org",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"references": [
{
"url": "https://lists.apache.org/thread/g43164t4bcp0tjwt4opxyks4svm8kvbh",
"source": "security@apache.org"
}
]
}