CVE-2018-1299
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 3.0%
probabilidad de explotación
3.0%top 13% de las CVE
explotación observada
noninguna fuente lo reporta
In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, such as Nginx, Apache/mod_wsgi or paster may prevent the attack from succeeding. Others, such as gunicorn do not prevent it and leave Allura vulnerable.
Productos afectados
Apache Software Foundation · Apache Allura