MEDIUM 5.3 NVD
CVE-2026-75099
Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgr
Unauthenticated REST disclosure of certain content items in Apache Allura.
This issue affects Apache Allura: through 1.19.1.
Users are recommended to upgrade to version 1.20.0, which fixes the issue.
References
- https://lists.apache.org/thread/lnsfx58o6mx6m44qk4vzqrq8ccmrywcy
- http://www.openwall.com/lists/oss-security/2026/08/24/6
- https://www.openwall.com/lists/oss-security/2026/08/24/6
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-24 via NVD.
vulnfeed aggregates 11313 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.