Impact
A weblog administrator can author a Velocity template that uses an include directive to load a classpath resource outside the theme namespace, bypassing the Velocity sandbox. This allows the reading of application classpath files, including configuration files containing secrets. The consequence is the exposure of sensitive information through an information‑disclosure vulnerability.
Affected Systems
Apache Roller versions preceding 6.1.6, notably 6.1.5, are impacted. Any weblog whose administrator has the ability to author templates is vulnerable, regardless of additional configuration changes.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be a weblog administrator and to author a template; no non‑default configuration is needed. The attack vector is therefore local to the web application context, relying on the presence of an privileged administrator user.
OpenCVE Enrichment