Описание
In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.
Ссылки
- Vendor Advisory
- MitigationThird Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Vendor Advisory
- MitigationThird Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.2 (включая) до 1.3.9 (включая)Версия от 2.0.0 (включая) до 2.2.3 (включая)
Одно из
cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01743
Низкий
6.5 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
EPSS
Процентиль: 82%
0.01743
Низкий
6.5 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo