Stored Cross-Site Scripting Vulnerability in Apache Archiva 2.2.4
CVE-2019-0213

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 April 2019

What is CVE-2019-0213?

In Apache Archiva prior to version 2.2.4, there is a vulnerability that allows for the injection of malicious XSS code into central configuration entries such as the logo URL. This issue primarily affects those with admin privileges who can modify configurations. Furthermore, if the communication between the user's browser and the Archiva server is compromised, the risk of exploitation is increased. Implementing proper security measures is essential to mitigate this vulnerability.

Affected Version(s)

Apache Archiva All versions prior to version 2.2.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.