PT-2026-99792 · Apache · Apache Roller
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Roller version 6.1.5
Description
An issue allows a weblog administrator to read files on the application classpath, including configuration files containing secrets. This occurs when a Velocity template is authored using an include directive to load a classpath resource outside the theme namespace. Although a Velocity sandbox is enabled to treat weblog administrators as untrusted, the include and parse directives are not confined by this sandbox. This affects any weblog where the administrator has permissions to author templates, regardless of the configuration.
Recommendations
Upgrade to Apache Roller version 6.1.6 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Roller