Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-36471

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allura from 1.0.1 through 1.16.0. Users are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.7%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-36471
  • Apache » Allura » Version: 1.0.1
    cpe:2.3:a:apache:allura:1.0.1
  • Apache » Allura » Version: 1.1.0
    cpe:2.3:a:apache:allura:1.1.0
  • Apache » Allura » Version: 1.10.0
    cpe:2.3:a:apache:allura:1.10.0
  • Apache » Allura » Version: 1.11.0
    cpe:2.3:a:apache:allura:1.11.0
  • Apache » Allura » Version: 1.11.1
    cpe:2.3:a:apache:allura:1.11.1
  • Apache » Allura » Version: 1.12.0
    cpe:2.3:a:apache:allura:1.12.0
  • Apache » Allura » Version: 1.13.0
    cpe:2.3:a:apache:allura:1.13.0
  • Apache » Allura » Version: 1.14.0
    cpe:2.3:a:apache:allura:1.14.0
  • Apache » Allura » Version: 1.15.0
    cpe:2.3:a:apache:allura:1.15.0
  • Apache » Allura » Version: 1.16.0
    cpe:2.3:a:apache:allura:1.16.0
  • Apache » Allura » Version: 1.2.0
    cpe:2.3:a:apache:allura:1.2.0
  • Apache » Allura » Version: 1.2.1
    cpe:2.3:a:apache:allura:1.2.1
  • Apache » Allura » Version: 1.3.0
    cpe:2.3:a:apache:allura:1.3.0
  • Apache » Allura » Version: 1.3.1
    cpe:2.3:a:apache:allura:1.3.1
  • Apache » Allura » Version: 1.3.2
    cpe:2.3:a:apache:allura:1.3.2
  • Apache » Allura » Version: 1.4.0
    cpe:2.3:a:apache:allura:1.4.0
  • Apache » Allura » Version: 1.5.0
    cpe:2.3:a:apache:allura:1.5.0
  • Apache » Allura » Version: 1.6.0
    cpe:2.3:a:apache:allura:1.6.0
  • Apache » Allura » Version: 1.7.0
    cpe:2.3:a:apache:allura:1.7.0
  • Apache » Allura » Version: 1.8.0
    cpe:2.3:a:apache:allura:1.8.0
  • Apache » Allura » Version: 1.8.1
    cpe:2.3:a:apache:allura:1.8.1
  • Apache » Allura » Version: 1.9.0
    cpe:2.3:a:apache:allura:1.9.0


Contact Us

Shodan ® - All rights reserved