U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-46911

Change History

New CVE Received from Apache Software Foundation 10/14/2024 5:15:04 AM

Action Type Old Value New Value
Added Description

								
							
							
						
Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF protections allowed an escalation of privileges attack. This issue affects Apache Roller before 6.1.4.

Roller users who run multi-blog/user Roller websites are recommended to upgrade to version 6.1.4, which fixes the issue.

Roller 6.1.4 release announcement:  https://lists.apache.org/thread/3c3f6rwqptyw6wdc95654fq5vlosqdpw
Added CWE

								
							
							
						
Apache Software Foundation CWE-352
Added Reference

								
							
							
						
Apache Software Foundation https://lists.apache.org/thread/6m0ghjo9j92qty00t2qb6qf2spds0p5t [No types assigned]