CVE-2024-46911
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-46911 is a privilege escalation vulnerability affecting Apache Roller, a popular open-source blogging platform. By default, weblog owners in multi-blog/user Roller websites have the ability to publish arbitrary content. A deficiency in Roller's Cross-Site Request Forgery (CSRF) protections enables an attacker to exploit this trust and escalate privileges, potentially gaining control over other users' weblogs. Roller users running multi-blog/user sites are urged to upgrade to version 6.1.4 to mitigate this issue. This release addresses the CSRF vulnerability, safeguarding the security of Roller installations. (Source: Apache Roller Security Advisory - <https://lists.apache.org/thread/3c3f6rwqptyw6wdc95654fq5vlosqdpw>)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Apache Roller
Affected Vendors
- Apache Corporation