Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted. This issue affects Apache Allura: from 1.4.0 through 1.17.0. Users are recommended to upgrade to version 1.17.1, which fixes the issue.
History

Thu, 19 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache allura
CPEs cpe:2.3:a:apache:allura:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache allura
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Fri, 13 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-06-22T09:09:32.464Z

Updated: 2024-09-13T16:03:27.951Z

Reserved: 2024-06-14T14:41:30.189Z

Link: CVE-2024-38379

cve-icon Vulnrichment

Updated: 2024-09-13T16:03:27.951Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-22T09:15:09.577

Modified: 2024-09-19T16:46:38.287

Link: CVE-2024-38379

cve-icon Redhat

No data.