CVE-2018-1299

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
06/02/2018
Last modified:
07/11/2023

Description

In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, such as Nginx, Apache/mod_wsgi or paster may prevent the attack from succeeding. Others, such as gunicorn do not prevent it and leave Allura vulnerable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:allura:*:*:*:*:*:*:*:* 1.8.0 (excluding)