CVE-2024-36471
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allura from 1.0.1 through 1.16.0. Users are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-200, CWE-918
- Affected
- apache/allura
- Source
- security@apache.org
References
- https://lists.apache.org/thread/g43164t4bcp0tjwt4opxyks4svm8kvbhMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/06/10/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/g43164t4bcp0tjwt4opxyks4svm8kvbhMailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.