Image

Blog Better! Roller is the open source Java blog server that drives Apache Software Foundation blogs and others. Read more on the about page.

Site hosted by Digital Ocean



Main | Next page »

Apache Roller 6.1.6 fixes 18 security vulnerabilities

09.27.2026 by Dave Johnson | 0 Comments

Apache Roller 6.1.6 fixes 18 security vulnerabilities. Apache Roller 6.1.5 is affected. Upgrade to 6.1.6 now.

Every installation should upgrade. Some vulnerabilities need no optional feature. Vulnerabilities were found in these features:

  • Comments & Trackbacks, LDAP comment authentication
  • Multiple users and weblogs
  • Media file uploads
  • The frontpage theme
  • XML-RPC (MetaWeblog or Blogger API), even when disabled
  • AtomPub with WSSE authentication
  • OAuth

Each CVE links to its advisory.

Critical

Important

Moderate

Some changes affect existing installations. Read the release notes before you upgrade.

Thanks to the reporters and to everyone who reviewed and tested the fixes.

Apache Roller 6.1.6 released

09.24.2026 by Dave Johnson | 0 Comments

The Apache Roller project is pleased to announce Apache Roller 6.1.6.

Roller is a full-featured, multi-user and group-blog server written in Java, suitable for blog sites large and small.

This is a maintenance release with bug fixes and small improvements. Users of 6.1.5 and earlier are encouraged to upgrade.

A few changes affect existing installations:

  • Initial setup now requires a one-time token that Roller prints to the server log. This applies both to a new installation and to a restart that migrates the database schema.
  • Incoming and outbound Trackback support is removed. The endpoint no longer exists and the entry editor no longer sends pings.
  • WSSE AtomPub authentication is retired. The authentication.method setting now takes basic or oauth, and an installation still set to wsse fails on startup, so change it before you upgrade.
  • Media file content types are derived from file content rather than from the upload request.
  • Table detection during installation is scoped to the database the connection points at. This fixes MySQL installs into an empty schema on a server that also hosts another Roller database.

Downloads · Release notes

Apache Roller 6.1.5 is available

04.09.2025 by Dave Johnson | 0 Comments

Roller 6.1.5 fixes CVE-2025-24859 (sessions not invalidated on password change), plus dependency updates and small bug fixes.[Read More]

Apache Roller 6.1.4 is available

10.10.2024 by Dave Johnson | 0 Comments

The Apache Roller project is pleased to announce the release of Roller 6.1.4! This release includes several updates and improvements to enhance the security, stability, and functionality of your Roller installations.

Dowload the latest release from: 

    https://www.apache.org/dyn/closer.cgi/roller/roller-6.1/v6.1.4

Key Changes in Apache Roller 6.1.4

Safer defaults

As of Roller 6.1.4, several default settings have been updated to enhance security for multi-user weblog sites:

  • HTML content sanitization: Roller now sanitizes all HTML content by default to prevent malicious content. This is controlled by the weblogAdminsUntrusted=true property in your roller-custom.properties file.
  • Custom themes and file-uploads disabled by default. You can enable this feature via the Server Admin page if you trust your users, as these features can pose security risks.
  • Better CSRF and XSS protection by user-specific and one-time-use salts.

Dependency updates

Over 20 mostly minor dependency updates including Spring, Eclipse-Link JPA, Log4j, Lucene, and more.

Bug fixes

Fixed some bugs that impacted category create, update and delete.

Apache Roller 6.1.3 is available

06.12.2024 by Dave Johnson | 0 Comments

The Apache Roller project is pleased to announce the availability of Roller 6.1.3, a release that includes some minor bug fixes, dependency updates and input sanitization changes. If you run a multi-user Roller site and you do not trust your users, you should upgrade as this release fixed a couple of XSS vulnerabiltiies.

https://roller.apache.org/downloads/downloads.html

You can find some more details about the release in the vote thread here:

https://lists.apache.org/thread/xnnf63bdzmq7z08ptdptyg5c30rfvzq5

Thanks to all who helped out with this release!

Apache Roller 6.1.2 is available

08.03.2023 by Dave Johnson | 0 Comments

The Apache Roller project is pleased to announce the availability of Roller 6.1.2, a release that includes some minor bug fixes and input sanitization changes.

https://roller.apache.org/downloads/downloads.html

You can find some more details about the release in the vote thread here:

https://lists.apache.org/thread/7wq8gb0g143zzbd6ds0c1k2zm51gbv2h   

Thanks to all who helped out with this release!

Apache Roller 6.1.1 release is available

04.30.2022 by Dave Johnson | 0 Comments

The Apache Roller project is pleased to announce the availability of Roller 6.1.1, a release that upgrades many dependencies including  Spring, Struts, Lucene, Log4J, Guice and Bouncy Castle. The release and convenience binaries can be found on the Roller project download page here:


You can find some more details about the release in the vote thread here:


Thanks to all who helped out with this release!

Apache Roller 6.1.0 release is available

12.22.2021 by Dave Johnson | 0 Comments

The Apache Roller project is pleased to announce the availability of Roller 6.1.0, a release that upgrades over a dozen dependencies (including Log4J) and includes a number of bug fixes and improvements to the code-base. The release and convenience binaries can be found on the Roller project downloads page here:

https://roller.apache.org/downloads/downloads.html

You can find some more details about the release in the vote thread here:

https://lists.apache.org/thread/7334kfm8g5mlq1g0y8783ldfopdfc3sc

Thanks to all who helped out with this release!
Main | Next page »