Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqcf-4g4h-rghf

Опубликовано: 14 мая 2019
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Cross-site scripting in Apache Archiva

In Apache Archiva before 2.2.4, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.

Пакеты

Наименование

org.apache.archiva:archiva

maven
Затронутые версииВерсия исправления

< 2.2.4

2.2.4

EPSS

Процентиль: 69%
0.00611
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
nvd
почти 7 лет назад

In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised.

EPSS

Процентиль: 69%
0.00611
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79