CVE-2024-36471

CVE-2024-36471: Apache Allura: sensitive information exposure via DNS rebinding

Vendor Apache Software Foundation
Product Apache Allura
Weakness CWE-20 · Input validation
Published June 10, 2024
Last update September 13, 2024

CVSS base score

What the vulnerability does

Description

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allura from 1.0.1 through 1.16.0. Users are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file.

Key dates

Disclosure timeline

June 10, 2024 CVE published
September 13, 2024 Record updated