CVE-2024-38379

CVE-2024-38379: Apache Allura: Stored authenticated XSS

Vendor Apache Software Foundation
Product Apache Allura
Weakness CWE-79 · XSS
Published June 22, 2024
Last update March 19, 2025

CVSS base score

What the vulnerability does

Description

Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted. This issue affects Apache Allura: from 1.4.0 through 1.17.0. Users are recommended to upgrade to version 1.17.1, which fixes the issue.

Key dates

Disclosure timeline

June 22, 2024 CVE published
March 19, 2025 Record updated