PT-2024-32280 · Apache · Apache Roller

Chi Tran

·

Published

2024-10-13

·

Updated

2024-11-01

·

CVE-2024-46911

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Roller versions prior to 6.1.4
Description A Cross-site Resource Forgery (CSRF) and privilege escalation vulnerability exists in Apache Roller. On multi-blog/user Roller websites, weblog owners are trusted to publish arbitrary weblog content by default. This, combined with a deficiency in Roller's CSRF protections, allows an escalation of privileges attack.
Recommendations To resolve the issue, upgrade to version 6.1.4, which fixes the problem. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-46911

Affected Products

Apache Roller