CVE-2024-25090: Apache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users mode
"David M. Johnson" <[email protected]> Thu, 25 Jul 2024 21:46:28 +0000
| Newsgroups | gmane.comp.java.roller.user |
|---|---|
| Message-ID | <[email protected]> |
Severity: low Affected versions: - Apache Roller 5.0.0 before 6.1.3 Description: Insufficient input validation and sanitation in Profile name & screenname, = Bookmark name & description and blogroll name features in all versions of = Apache Roller on all platforms allows an authenticated user to perform an = XSS attack. Mitigation: if you do not have Roller configured for untrusted = users, then you need to do nothing because you trust your users to author = raw HTML and other web content. If you are running with untrusted users = then you should upgrade to Roller 6.1.3. This issue affects Apache Roller: from 5.0.0 before 6.1.3. Users are recommended to upgrade to version 6.1.3, which fixes the issue. Credit: Jacob Hazak (reporter) References: https://roller.apache.org/ https://www.cve.org/CVERecord?id=3DCVE-2024-25090