Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF protections allowed an escalation of privileges attack. This issue affects Apache Roller before 6.1.4.
Roller users who run multi-blog/user Roller websites are recommended to upgrade to version 6.1.4, which fixes the issue.
Roller 6.1.4 release announcement: https://lists.apache.org/thread/3c3f6rwqptyw6wdc95654fq5vlosqdpw
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 15 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 14 Oct 2024 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF protections allowed an escalation of privileges attack. This issue affects Apache Roller before 6.1.4. Roller users who run multi-blog/user Roller websites are recommended to upgrade to version 6.1.4, which fixes the issue. Roller 6.1.4 release announcement: https://lists.apache.org/thread/3c3f6rwqptyw6wdc95654fq5vlosqdpw | |
Title | Apache Roller: Weakness in CSRF protection allows privilege escalation | |
Weaknesses | CWE-352 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-10-14T08:13:05.578Z
Updated: 2024-11-01T17:06:11.070Z
Reserved: 2024-09-15T18:44:35.231Z
Link: CVE-2024-46911
Vulnrichment
Updated: 2024-10-14T09:03:17.746Z
NVD
Status : Awaiting Analysis
Published: 2024-10-14T09:15:04.297
Modified: 2024-11-01T17:35:07.877
Link: CVE-2024-46911
Redhat
No data.