/plushcap/analysis/sonar/dangerous-import-sourceforge-patches-critical-code-vulnerability

Dangerous Import: SourceForge Patches Critical Code Vulnerability

What's this blog post about?

In October 2023, Sonar's Vulnerability Research Team discovered a critical code vulnerability (CVE-2023-46851) in the Apache Allura software used by SourceForge. This vulnerability could have allowed attackers to fully compromise SourceForge and spread malicious software to nearly 20 million users worldwide. The issue was fixed with Apache Allura version 1.16.0, and there were no signs of in-the-wild exploitation.

Company
Sonar

Date published
April 16, 2024

Author(s)
Stefan Schiller

Word count
1192

Language
English

Hacker News points
None found.


By Matt Makai. 2021-2024.