Impact
The vulnerability is a cross‑site scripting flaw in the code display feature of Apache Allura. An attacker who can supply or influence the displayed code can inject malicious script that runs in the browser of any user who views that content, potentially leading to session hijacking, credential theft, or defacement within the victim's session.
Affected Systems
All versions of Apache Allura from the Apache Software Foundation before 1.19.1 are affected; this includes any installations running an earlier release of Allura.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity. The exploit requires the attacker to influence the code displayed and depends on a user viewing the compromised content; no publicly available exploit is currently documented, and the vulnerability is not listed in CISA's KEV catalog. Because the attack vector is web‑based and the victim must interact with the affected UI, the overall risk is moderate, but an attacker with access to the code preview function can leverage it during a user session.
OpenCVE Enrichment