In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, such as Nginx, Apache/mod_wsgi or paster may prevent the attack from succeeding. Others, such as gunicorn do not prevent it and leave Allura vulnerable.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2018-02-06T19:00:00Z
Updated: 2024-09-16T21:07:54.673Z
Reserved: 2017-12-07T00:00:00
Link: CVE-2018-1299
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-02-06T20:29:00.253
Modified: 2024-11-21T03:59:34.407
Link: CVE-2018-1299
Redhat
No data.