CVE-2024-46911

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Oct 14, 2024
Updated: Nov 21, 2024
CWE ID 352

Summary

CVE-2024-46911 is a privilege escalation vulnerability affecting Apache Roller, a popular open-source blogging platform. By default, weblog owners in multi-blog/user Roller websites have the ability to publish arbitrary content. A deficiency in Roller's Cross-Site Request Forgery (CSRF) protections enables an attacker to exploit this trust and escalate privileges, potentially gaining control over other users' weblogs. Roller users running multi-blog/user sites are urged to upgrade to version 6.1.4 to mitigate this issue. This release addresses the CSRF vulnerability, safeguarding the security of Roller installations. (Source: Apache Roller Security Advisory - <https://lists.apache.org/thread/3c3f6rwqptyw6wdc95654fq5vlosqdpw>)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache Roller

Affected Vendors

  • Apache Corporation