Stored Cross-Site Scripting Vulnerability in Apache Archiva 2.2.4
CVE-2019-0213

6.5MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
30 April 2019

Summary

In Apache Archiva prior to version 2.2.4, there is a vulnerability that allows for the injection of malicious XSS code into central configuration entries such as the logo URL. This issue primarily affects those with admin privileges who can modify configurations. Furthermore, if the communication between the user's browser and the Archiva server is compromised, the risk of exploitation is increased. Implementing proper security measures is essential to mitigate this vulnerability.

Affected Version(s)

Apache Archiva All versions prior to version 2.2.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.