archiva-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Martin <marti...@apache.org>
Subject [SECURITY] CVE-2019-0214: Apache Archiva arbitrary file write and delete on the server
Date Tue, 30 Apr 2019 15:23:22 GMT
CVE-2019-0214: Apache Archiva arbitrary file write and delete on the server

Severity: Medium

Vendor:
The Apache Software Foundation

Versions Affected:
    Apache Archiva 2.0.0 - 2.2.3
    The unsupported versions 1.x are also affected.  

It is possible to write files to the archiva server at arbitrary locations by using the artifact
upload mechanism. 
Existing files can be overwritten, if the archiva run user has appropriate permission on the
filesystem for the target file.

Mitigation:
  It is highly recommended to upgrade to Archiva 2.2.4 or higher, where additional validations
are implemented to prevent such malicious parameter values.
  As intermediate action you may reduce the number of users that are allowed to upload to
archiva and make sure, that the archiva run user may have only 
  write permission to the directories needed.

References:
http://archiva.apache.org/security.html#CVE-2019-0214

The newest Archiva version can be downloaded from:
http://archiva.apache.org/download.cgi




Mime
View raw message