Known vulnerabilities in Allura
Vendor:
Apache Foundation
Software:
Allura
Software CPE:
cpe:2.3:a:apache_foundation:allura:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU93076 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-38379 |
CWE-79 | Low | 1.17.1 | 22.06.2024 |
SB2024062206 |
||
| #VU93075 - Exposure of sensitive information to an unauthorized actor CVE-2024-36471 |
CWE-200 | Low | 1.17.0 | 22.06.2024 |
SB2024062205 |
||
| #VU93074 - Exposure of sensitive information to an unauthorized actor CVE-2023-46851 |
CWE-200 | Low | 1.16.0 | 22.06.2024 |
SB2024062204 |
||
| #VU93073 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-10085 |
CWE-79 | Low | 1.11.0 | 22.06.2024 |
SB2019061964 |
||
| #VU93072 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2018-1319 |
CWE-113 | Medium | 1.8.1 | 22.06.2024 |
SB2018031546 |
||
| #VU93071 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2018-1299 |
CWE-22 | Medium | 1.8.0 | 22.06.2024 |
SB2018020624 |