Known vulnerabilities in Allura

Software: Allura
Software CPE: cpe:2.3:a:apache_foundation:allura:*:*:*:*:*:*:*:*
Total vulnerabilities: 6
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Allura Allura is affected by 6 known vulnerabilities: 2 medium, 4 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU93076 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-38379
CWE-79 Low
No
No
1.17.1 22.06.2024 SB2024062206
#VU93075 - Exposure of sensitive information to an unauthorized actor
CVE-2024-36471
CWE-200 Low
No
No
1.17.0 22.06.2024 SB2024062205
#VU93074 - Exposure of sensitive information to an unauthorized actor
CVE-2023-46851
CWE-200 Low
No
No
1.16.0 22.06.2024 SB2024062204
#VU93073 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-10085
CWE-79 Low
No
No
1.11.0 22.06.2024 SB2019061964
#VU93072 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2018-1319
CWE-113 Medium
No
No
1.8.1 22.06.2024 SB2018031546
#VU93071 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-1299
CWE-22 Medium
No
No
1.8.0 22.06.2024 SB2018020624