Количество 2
Количество 2
CVE-2019-0213
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised.
GHSA-cqcf-4g4h-rghf
Cross-site scripting in Apache Archiva
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-0213 In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised. | CVSS3: 6.5 | 1% Низкий | почти 7 лет назад | |
GHSA-cqcf-4g4h-rghf Cross-site scripting in Apache Archiva | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу