Severity: Moderate
CVSS 3.1: 9.0 (critical) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected versions:
- Apache Roller 6.1.5
Description:
Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache
Roller 6.1.5 allows an unauthenticated remote attacker who learns an
outstanding request token for a configured site-wide consumer to bind that
token to an arbitrary user account, including an administrator, by submitting
an unsigned authorization request. The endpoint derives the authorizing
identity from a request-supplied value rather than the authenticated session.
Only installations that configure an OAuth 1.0a site-wide consumer are
affected, and exploitation requires knowledge of one of its outstanding request
tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which
binds authorization to the logged-in session.
Credit:
meifukun (finder)
References:
https://github.com/apache/roller/pull/165
https://roller.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-82378