CVE-2019-0213
published 2019-04-30CVE-2019-0213: In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is…
PriorityP339medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
4.93%
91.2th percentile
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_archiva | — | — |
| apache | archiva | < 2.2.4 | 2.2.4 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cross-site scripting in Apache Archiva
ghsa·2019-05-14
CVE-2019-0213 [MEDIUM] CWE-79 Cross-site scripting in Apache Archiva
Cross-site scripting in Apache Archiva
In Apache Archiva before 2.2.4, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.
OSV
Cross-site scripting in Apache Archiva
osv·2019-05-14
CVE-2019-0213 [MEDIUM] Cross-site scripting in Apache Archiva
Cross-site scripting in Apache Archiva
In Apache Archiva before 2.2.4, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.
No detection rules found.
No public exploits indexed.
http://archiva.apache.org/security.html#CVE-2019-0213http://packetstormsecurity.com/files/152681/Apache-Archiva-2.2.3-Cross-Site-Scripting.htmlhttp://www.openwall.com/lists/oss-security/2019/04/30/7http://www.securityfocus.com/bid/108123https://lists.apache.org/thread.html/0397ddbd17b5257cc1746b31a07294a87221c5ca24e5d19d390e28f3%40%3Cusers.archiva.apache.org%3Ehttps://lists.apache.org/thread.html/7bcea134c3d6fa72cdc1052922ac0914f399f63f4690b7937b80127d%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/ada0052409d8a4a8c4eb2c7fd6b9cd9423bc753d5fce87eb826662fb%40%3Cissues.archiva.apache.org%3Ehttps://lists.apache.org/thread.html/c358754a35473a61477f9d487870581a0dd7054ff95974628fa09f97%40%3Cusers.maven.apache.org%3Ehttps://seclists.org/bugtraq/2019/Apr/47http://archiva.apache.org/security.html#CVE-2019-0213http://packetstormsecurity.com/files/152681/Apache-Archiva-2.2.3-Cross-Site-Scripting.htmlhttp://www.openwall.com/lists/oss-security/2019/04/30/7http://www.securityfocus.com/bid/108123https://lists.apache.org/thread.html/0397ddbd17b5257cc1746b31a07294a87221c5ca24e5d19d390e28f3%40%3Cusers.archiva.apache.org%3Ehttps://lists.apache.org/thread.html/7bcea134c3d6fa72cdc1052922ac0914f399f63f4690b7937b80127d%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/ada0052409d8a4a8c4eb2c7fd6b9cd9423bc753d5fce87eb826662fb%40%3Cissues.archiva.apache.org%3Ehttps://lists.apache.org/thread.html/c358754a35473a61477f9d487870581a0dd7054ff95974628fa09f97%40%3Cusers.maven.apache.org%3Ehttps://seclists.org/bugtraq/2019/Apr/47
2019-04-30
Published