Impact
The vulnerability is a missing authentication check on the setup action of Apache Roller 6.1.5, classified as CWE‑306. Because the setup endpoint remains reachable after installation, an unauthenticated remote user can continuously change the global configuration that selects the frontpage weblog. This can redirect site visitors to a malicious page or break the public frontpage, while only requiring plain HTTP requests. Administrative recovery is possible by reverting the configuration, but the attack can persist until the system is patched.
Affected Systems
Affected systems are deployments of Apache Roller version 6.1.5. Upgrading to version 6.1.6 or newer limits write access on the setup action to global administrators, eliminating the flaw. No other product or version is listed in the CNA data.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, and the vulnerability is exploitable remotely without any authentication or special configuration. Because the EPSS score is unavailable and the issue is not yet in the CISA KEV catalog, there is no known exploitation data, but the attack vector is straightforward: any host running the affected version is at risk of remote configuration tampering. The lack of an authorization check allows an attacker to keep the change persistent, making remediation a high priority.
OpenCVE Enrichment