Advertisement






Apache Archiva 2.2.3 Cross Site Scripting

CVE Category Price Severity
CVE-2019-0213 CWE-79 $1,000 High
Author Risk Exploitation Type Date
George Foundaras High Remote 2019-05-01
CPE
cpe:cpe:/a:apache:archiva:2.2.3
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019050011

Below is a copy:

Apache Archiva 2.2.3 Cross Site Scripting
CVE-2019-0213: Apache Archiva Stored XSS

Severity: Low

Vendor:
The Apache Software Foundation

Versions Affected:
    Apache Archiva 2.0.0 - 2.2.3
    The unsupported versions 1.x are also affected.  

It may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. 
The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication 
between the browser and the Archiva server must be compromised. 

Mitigation:
  All users are recommended to upgrade to Archiva 2.2.4 or higher, 

References:
http://archiva.apache.org/security.html#CVE-2019-0213

The newest Archiva version can be downloaded from:
http://archiva.apache.org/download.cgi


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum