CVE-2019-0214

Severity
6.5MEDIUM
EPSS
1.6%
top 18.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 14

Description

In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

Mavenorg.apache.archiva:archiva2.2.02.2.4
NVDapache/archiva1.21.3.9+1
CVEListV5apache/apache_archivaAll versions prior to version 2.2.4

🔴Vulnerability Details

3
OSV
Improper Input Validation in Apache Archiva2019-05-14
GHSA
Improper Input Validation in Apache Archiva2019-05-14
CVEList
CVE-2019-0214: In Apache Archiva 22019-04-30
CVE-2019-0214 (MEDIUM CVSS 6.5) | In Apache Archiva 2.0.0 - 2.2.3 | cvebase.io