Advertisement






Apache Archiva 2.2.3 File Write / Delete

CVE Category Price Severity
CVE-2019-0214 CWE-XXXX Unknown High
Author Risk Exploitation Type Date
Unknown Critical Remote 2019-05-01
CPE
cpe:cpe:/a:apache:archiva:2.2.3
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019050016

Below is a copy:

Apache Archiva 2.2.3 File Write / Delete
CVE-2019-0214: Apache Archiva arbitrary file write and delete on the server

Severity: Medium

Vendor:
The Apache Software Foundation

Versions Affected:
    Apache Archiva 2.0.0 - 2.2.3
    The unsupported versions 1.x are also affected.  

It is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. 
Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.

Mitigation:
  It is highly recommended to upgrade to Archiva 2.2.4 or higher, where additional validations are implemented to prevent such malicious parameter values.
  As intermediate action you may reduce the number of users that are allowed to upload to archiva and make sure, that the archiva run user may have only 
  write permission to the directories needed.

References:
http://archiva.apache.org/security.html#CVE-2019-0214

The newest Archiva version can be downloaded from:
http://archiva.apache.org/download.cgi


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum