CVE-2026-82375 Apache Roller 服务端请求伪造漏洞
影响认证用户可发起服务端请求,探测内网与回环地址
Apache Roller 6.1.5 存在服务端请求伪造(SSRF)漏洞。拥有博客文章编辑权限的认证用户可通过遗留的 Trackback 出站处理与文章 enclosure 处理,让服务器向攻击者指定的任意地址发起 HTTP 请求。默认空白的 Trackback 允许列表不限制目标,因此可访问回环与内网地址。
影响范围
Apache Roller 6.1.5;官方建议升级至 6.1.6 或更高版本。
漏洞详情
漏洞类型为 SSRF,成因是旧版 Trackback 出站动作虽在标准界面隐藏但仍可直接调用,且 enclosure 处理会解引用作者提供的 URL。攻击者利用文章编辑权限构造请求,使服务器向任意目标发起出站 HTTP 请求;enclosure 路径还会回显响应状态码、内容类型与长度,可用于内网探测。
利用条件与风险
利用需具备博客文章编辑权限的认证账号,无需非默认配置,默认允许列表为空即放行所有目标,实战中可用于内网资产探测与信息泄露。
修复建议
升级至 Apache Roller 6.1.6 或更高版本,该版本移除了出站 Trackback 动作并停止解引用 enclosure URL;若无法立即升级,可限制文章编辑权限或通过网络层限制服务器出站访问。
Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard UI, but its action remains directly reachable; the enclosure path is relevant only when an author supplies an enclosure URL. No non-default server configuration is required, and the default empty Trackback allow-list permits all destinations. Requests can reach loopback and private-network addresses, while enclosure handling exposes response status, content type, and length. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback action and stops dereferencing enclosure URLs.