PT-2026-99798 · Apache · Apache Roller
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Apache Roller version 6.1.5
Description
An authenticated user with entry-editing rights can trigger outbound HTTP requests to arbitrary destinations via legacy outbound Trackback and entry enclosure handling. Although the Trackback control is hidden in the standard UI, the action remains accessible. The issue occurs when an author provides an enclosure URL. Because the default Trackback allow-list is empty, it permits all destinations, including loopback and private-network addresses. Additionally, enclosure handling reveals the response status, content type, and length of the requested destination.
Recommendations
Upgrade to Apache Roller versions 6.1.6 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Roller