PT-2026-99803 · Apache · Apache Roller
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Apache Roller version 6.1.5
Description
Missing authentication for a critical function allows an unauthenticated remote attacker to persistently change a site-global configuration value regarding the frontpage weblog selection. This occurs because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. This issue can result in the redirection or disruption of the site's public frontpage.
Recommendations
Upgrade Apache Roller to version 6.1.6 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Roller