Vulnerabilities > Apache > Allura > 1.11.0

DATE CVE VULNERABILITY TITLE RISK
2024-06-22 CVE-2024-38379 Unspecified vulnerability in Apache Allura
Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted. This issue affects Apache Allura: from 1.4.0 through 1.17.0. Users are recommended to upgrade to version 1.17.1, which fixes the issue.
network
low complexity
apache
4.8
2023-11-07 CVE-2023-46851 Unspecified vulnerability in Apache Allura
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments.
network
low complexity
apache
4.9