Impact
Apache Allura allows users to perform a search that can reveal non-public information, leading to a breach of confidentiality. The issue is identified as a content exposure flaw and is classified under CWE-200. The vulnerability does not provide remote code execution or denial of service; it strictly exposes sensitive data through the search functionality.
Affected Systems
The affected product is Apache Allura, produced by the Apache Software Foundation. All versions up to and including 1.20.0 are impacted by this information disclosure. Users should confirm the exact version and compare it against the fixed release, 1.21.0.
Risk and Exploitability
The exploit probability is not quantified (EPSS score unavailable), and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, any system running the affected Allura releases could be compelled to reveal confidential data via the search feature. The primary risk is a confidentiality breach that could expose user data, project secrets, or internal system information. Since the flaw does not require special privileges beyond search access, it may be readily exploitable in a shared or public environment.
OpenCVE Enrichment