Impact
Apache Roller 6.1.5 implements an outbound trackback response parser that does not disable external entity resolution. An attacker who can create or edit a weblog entry can influence the XML payload sent to this parser, causing the server to resolve external entities. This leads to arbitrary file read vulnerabilities on the Roller process. The flaw permits disclosure of content readable by the Roller user account, potentially leaking sensitive configuration or host files.
Affected Systems
The issue affects Apache Roller projects running version 6.1.5 (and earlier) under the Apache Software Foundation. Upgrade to version 6.1.6 or later removes the vulnerable outbound trackback response parser, thereby eliminating the risk. No specific configuration changes are required to trigger the vulnerability.
Risk and Exploitability
With a CVSS score of 7.7 this vulnerability is categorized as high severity. The EPSS score is not available, but the flaw exploits a lack of external entity sanitization and can be triggered by any user with entry‑editing rights, a role that is often widely granted. The vulnerability is not listed in the CISA KEV catalog, yet because the attack does not require special server settings and the hidden trackback endpoint is still reachable, there is a realistic threat to systems running vulnerable versions.
OpenCVE Enrichment