Severity: important Affected versions:
- Apache Allura through 1.19.1 Description: Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue. Credit: Venkatraman Kumar, securin.io (finder) References: https://allura.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-75099
