Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgr…
Info
Summary
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://allura.apache.org/posts/2026-allura-1.19.1.html
- https://lists.apache.org/thread/ryn6yomo897d43ovrd47g02t8ycmbxb3
- http://www.openwall.com/lists/oss-security/2026/08/12/18
Timeline
- nvd_ingest NVD