Impact
Apache Roller’s XML parser accepts external entity references in OPML files when an administrator imports bookmarks. A crafted OPML document can include entities that read arbitrary files readable by the Roller process and points to internal network addresses, enabling a privileged administrator to expose sensitive data and potentially pivot into the internal network. The vulnerability is not a classic remote code execution flaw, but it does allow a logged‑in administrator to read files beyond normal application boundaries and reach internal hosts.
Affected Systems
The flaw exists in Apache Roller 6.1.5 and earlier releases from the Apache Software Foundation. Users of these versions should check whether they are running the affected code base and plan an upgrade.
Risk and Exploitability
The CVSS score of 7.7 categorises this as High severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires administrative access to the bookmark‑import function and no special configuration is required, making the attack vector straightforward for an authorised user or an attacker who has compromised an administrator account.
OpenCVE Enrichment