https://seclists.org/oss-sec/2024/q2/294: CVE-2024-38379: Apache Allura: Stod authenticated XSS
Published Jun 21, 2024
·Updated
Affected Software
1 affected component
Apache Allura>=1.4.0<1.17.0
Frequently Asked Questions
1
What is the severity of CVE-2024-38379?
The severity of CVE-2024-38379 is classified as moderate.
2
Which versions of Apache Allura are affected by CVE-2024-38379?
Apache Allura versions 1.4.0 through 1.17.0 are affected by CVE-2024-38379.
3
What type of vulnerability is CVE-2024-38379?
CVE-2024-38379 is a stored cross-site scripting (XSS) vulnerability.
4
Who is impacted by CVE-2024-38379?
The impact of CVE-2024-38379 is limited to neighborhood admins who can access vulnerable settings.
5
How do I fix CVE-2024-38379?
To fix CVE-2024-38379, upgrade to a version of Apache Allura later than 1.17.0.