CVE-2026-82386 Apache Roller XXE 漏洞
影响管理员可读取服务器文件并探测内网
Apache Roller 6.1.5 的书签导入功能在解析 OPML 文档时未禁用外部实体解析,存在 XML 外部实体注入(XXE)问题。拥有管理员权限的攻击者可通过导入特制 OPML 文件读取 Roller 进程可访问的文件,并访问内网地址。
影响范围
Apache Roller 6.1.5 受影响;官方已在 6.1.6 及更高版本中修复。
漏洞详情
漏洞类型为 XXE(XML 外部实体注入)。成因是书签导入解析器未禁用外部实体解析和文档类型声明,导致解析 OPML 时会加载攻击者指定的外部实体。攻击者通过管理员书签导入操作上传特制 OPML 文档,即可读取本地文件或发起内网请求。
利用条件与风险
利用需要具备 weblog 管理员权限,且无需非默认配置即可通过书签导入功能触发。实战中可用于读取配置文件、凭据等敏感信息并探测内网服务。
修复建议
升级至 Apache Roller 6.1.6 或更高版本,该版本使用禁用外部实体和文档类型声明的加固解析器。临时缓解措施暂无公开信息。
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator bookmark-import action. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which uses a hardened parser that disables external entities and document type declarations.