Impact
An unauthenticated REST API can expose sensitive content items within Apache Allura, allowing an attacker to view data that should be protected by authentication controls. This flaw is classified as CWE‑200, which denotes improper restriction of data access. The consequence is the disclosure of potentially confidential information to anyone who can reach the vulnerable endpoints.
Affected Systems
Apache Allura versions up through 1.19.1 are vulnerable. The issue is known to affect all installations of Allura that have not been updated to version 1.20.0 or later.
Risk and Exploitability
The flaw can be exploited by making unauthenticated HTTP requests to the REST interfaces; no additional authentication or privilege is required. The CVSS score is 5.3. While an EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, the lack of restriction on the endpoints means that the risk to exposed data exists as soon as the application is reachable from an external network. No known exploits have been reported, but the straightforward attack surface warrants prompt remediation.
OpenCVE Enrichment