archiva-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Martin <marti...@apache.org>
Subject [SECURITY] CVE-2019-0213: Apache Archiva Stored XSS
Date Tue, 30 Apr 2019 15:18:58 GMT
CVE-2019-0213: Apache Archiva Stored XSS

Severity: Low

Vendor:
The Apache Software Foundation

Versions Affected:
    Apache Archiva 2.0.0 - 2.2.3
    The unsupported versions 1.x are also affected.  

It may be possible to store malicious XSS code into central configuration entries, i.e. the
logo URL. 
The vulnerability is considered as minor risk, as only users with admin role can change the
configuration, or the communication 
between the browser and the Archiva server must be compromised. 

Mitigation:
  All users are recommended to upgrade to Archiva 2.2.4 or higher, 

References:
http://archiva.apache.org/security.html#CVE-2019-0213

The newest Archiva version can be downloaded from:
http://archiva.apache.org/download.cgi




Mime
View raw message