oss-sec mailing list archives
CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure
From: Dave Brondsema <dave () brondsema net>
Date: Mon, 24 Aug 2026 12:19:24 -0400
Severity: important Affected versions: - Apache Allura through 1.19.1 Description: Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue. Credit: Venkatraman Kumar, securin.io (finder) References: https://allura.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-75099
Current thread:
- CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure Dave Brondsema (Aug 24)
