PT-2026-99796 · Apache · Apache Roller
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Roller version 6.1.5
Description
Improper neutralization of input during web page generation allows a remote attacker to perform reflected cross-site scripting (XSS) through the optional LDAP comment authenticator. The issue occurs because the
LdapCommentAuthenticator writes request parameter values into its HTML form without proper escaping. This affects only sites configured to use the LdapCommentAuthenticator, and requires a victim whose session has already loaded the authenticator form to follow a crafted link.Recommendations
Upgrade to Apache Roller versions 6.1.6 or later.
As a temporary mitigation, restrict the use of the
LdapCommentAuthenticator until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Roller