Impact
Authentication is required, but an account with entry‑editing rights can trigger outbound HTTP requests to any target chosen by the attacker. The legacy outbound trackback handler and the enclosure URL processor perform the requests, and the default allow‑list is empty, permitting all destinations. Because the mechanism can reach loopback and private addresses, an attacker can probe internal services, exfiltrate information about internal networks, and potentially cause denial of service by directing traffic to critical resources. The response status, content type, and length are exposed, giving the attacker additional visibility into internal endpoints.
Affected Systems
Apache Software Foundation’s Apache Roller, vulnerable in version 6.1.5 and all earlier releases that contain the legacy outbound trackback and enclosure URL handling logic.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, and the vulnerability is not currently catalogued in CISA’s KEV list. The EPSS score is not available, but the lack of configuration prerequisites and the ability to target internal networks imply a significant exploitability risk. An authenticated user can directly invoke the vulnerable endpoints without any additional setup, making this a practical attack vector inside the organization.
OpenCVE Enrichment