天下漏洞,尽知其名
HIGH

CVE-2026-82383 Apache Roller 关键功能缺失认证漏洞

影响未授权攻击者可篡改站点全局配置,导致首页被重定向或破坏

AI 研判

Apache Roller 6.1.5 存在关键功能缺失认证漏洞。安装完成后,setup 动作仍可被匿名访问,且写入全局配置时未做授权校验,导致未认证远程攻击者可持久修改站点首页博客选择。官方已在 6.1.6 中限制该写入仅限全局管理员。

影响范围

Apache Roller

Apache Roller 6.1.5;官方建议升级至 6.1.6 或更高版本。

漏洞详情

漏洞类型为关键功能缺失认证(CWE-306)。成因是安装完成后 setup 相关动作未做访问控制,匿名用户仍可调用,且修改站点全局配置(首页 weblog 选择)时缺少授权检查。攻击者无需登录即可发送请求,将配置持久化写入,从而重定向或破坏站点公开首页。

利用条件与风险

利用无需认证、无需非默认配置或可选功能,远程即可触发,实战风险较高;但影响限于篡改首页配置,管理员可恢复。

修复建议

升级至 Apache Roller 6.1.6 或更高版本,该版本将写入操作限制为全局管理员;临时缓解措施暂无公开信息。

原始情报

Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default configuration is required; the result can redirect or break the site’s public frontpage, with administrative recovery available. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts the write to global administrators.