Overview

Apache Allura provided by The Apache Software Foundation contains a server-side request forgery vulnerability.

Products Affected

  • Apache Allura versions prior to 1.19.1

Description

Apache Allura provided by The Apache Software Foundation contains the vulnerability listed below:

  • Server-side request forgery (CWE-918)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L Base Score 5.1
    • CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L Base Score 6.6
    • CVE-2026-69223

Impact

An attacker could use webhooks to send arbitrary requests to internal network URLs accessible from the affected product.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status
Vendor Link
The Apache Software Foundation Apache Allura 1.19.1 released, with many security fixes
References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC
Credit

Satoshi Ogawa of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000116

expand_less