天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-82379 Apache Roller 重放认证绕过漏洞

影响攻击者可重放认证头冒充受害者获取AtomPub权限

AI 研判

Apache Roller 6.1.5 的 AtomPub API 在启用 WSSE 认证时,未校验 nonce 唯一性和时间戳新鲜度,导致捕获到的合法 WSSE 摘要认证头可被重放。攻击者借此获得受害者的 AtomPub 权限,属于认证绕过类漏洞。

影响范围

Apache Roller

Apache Roller 6.1.5;仅影响启用了非默认 AtomPub API 且使用 WSSE 认证、并采用明文兼容密码存储的安装实例。

漏洞详情

漏洞类型为认证绕过(捕获重放)。WSSE 摘要认证头在服务端校验时未强制 nonce 唯一、也未检查时间戳是否过期,因此同一认证头可被反复使用。攻击者只需在网络中捕获一次有效认证请求,即可重放该头冒充原用户访问 AtomPub 接口。

利用条件与风险

利用前提是目标启用了非默认的 AtomPub API 与 WSSE 认证,且攻击者能捕获到有效认证头(如中间人、日志泄露等)。满足条件时可直接绕过认证,实战风险较高。

修复建议

官方建议升级至 Apache Roller 6.1.6 或更高版本,该版本移除了 WSSE 作为 AtomPub 认证方式;已配置 WSSE 的实例将默认失败关闭,需管理员显式选择受支持的认证方式。临时缓解可禁用 AtomPub API 或改用其他认证机制。

原始情报

Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim’s AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storage are affected. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes WSSE as an AtomPub authentication method; existing installations configured for WSSE fail closed until an administrator explicitly selects a supported authentication method.