https://seclists.org/oss-sec/2024/q3/113: CVE-2024-25090: Apache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users mode
Published Jul 25, 2024
·Updated
Affected Software
1 affected component
Apache Roller<6.1.3
Frequently Asked Questions
1
What is the severity of CVE-2024-25090?
The severity of CVE-2024-25090 is rated as low.
2
What versions of Apache Roller are affected by CVE-2024-25090?
Apache Roller versions 5.0.0 before 6.1.3 are affected by CVE-2024-25090.
3
How do I fix CVE-2024-25090?
To fix CVE-2024-25090, upgrade Apache Roller to version 6.1.3 or later.
4
What specific features are vulnerable in CVE-2024-25090?
CVE-2024-25090 affects the profile name, screenname, bookmark name, description, and blogroll name features.
5
Can authenticated users exploit CVE-2024-25090?
Yes, an authenticated user can exploit the insufficient input validation in CVE-2024-25090.