天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-82385 Apache Roller 敏感信息泄露漏洞

影响博客管理员可读取应用类路径下的敏感配置文件

AI 研判

Apache Roller 6.1.5 的 Velocity 模板沙箱未限制 include 与 parse 指令,导致拥有模板编辑权限的博客管理员可加载主题命名空间之外的类路径资源。攻击者可借此读取 Roller 配置文件中的密钥等敏感信息。该漏洞无需非默认配置即可触发。

影响范围

Apache Roller

Apache Roller 6.1.5;官方建议升级至 6.1.6 或更高版本。

漏洞详情

漏洞类型为敏感信息泄露。Roller 将博客管理员视为不可信用户并启用 Velocity 沙箱,但沙箱未约束 include/parse 指令,管理员可编写模板通过 include 指令加载类路径资源。由于读取范围超出当前主题命名空间,配置文件中的密钥等信息被暴露。

利用条件与风险

利用前提是攻击者拥有博客管理员权限并能编辑模板,无需其他非默认配置。实战中可导致配置密钥泄露,进而可能引发进一步横向利用,但需先获得管理员账户。

修复建议

官方修复方案为升级至 Apache Roller 6.1.6 或更高版本,该版本将 include 限制在当前活动主题内并移除博客渲染中的类路径资源加载。临时缓解措施暂无公开信息。

原始情报

Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.