https://seclists.org/oss-sec/2024/q4/21: CVE-2024-46911: Apache Roller: Weakness in CSRF protection allows privilege escalation
Published Oct 11, 2024
·Updated
Affected Software
1 affected component
Apache Roller<6.1.4
Frequently Asked Questions
1
What is the severity of CVE-2024-46911?
CVE-2024-46911 has been classified as an important severity vulnerability.
2
Which versions of Apache Roller are affected by CVE-2024-46911?
CVE-2024-46911 affects Apache Roller versions 1.0.0 prior to 6.1.4.
3
How do I fix CVE-2024-46911?
To address CVE-2024-46911, upgrade Apache Roller to version 6.1.4 or later.
4
What type of vulnerability is CVE-2024-46911?
CVE-2024-46911 is a Cross-site Resource Forgery (CSRF) vulnerability that can lead to privilege escalation.
5
What can happen if CVE-2024-46911 is exploited?
Exploitation of CVE-2024-46911 can allow unauthorized users to escalate their privileges on multi-blog/user Roller websites.