CVE-2018-1299

CWE-22Path Traversal3 documents3 sources
Severity
7.5HIGH
EPSS
0.7%
top 29.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 14

Description

In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, such as Nginx, Apache/mod_wsgi or paster may prevent the attack from succeeding. Others, such as gunicorn do not prevent it and leave Allura vulnerable.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/allura< 1.8.0

🔴Vulnerability Details

2
GHSA
GHSA-693w-mp32-8pwq: In Apache Allura before 12022-05-14
CVEList
CVE-2018-1299: In Apache Allura before 12018-02-06