Логотип exploitDog
bind:CVE-2024-27140
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-27140

Количество 2

Количество 2

nvd логотип

CVE-2024-27140

почти 2 года назад

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Alternatively, you could configure a HTTP proxy in front of your Archiva instance to only forward requests that do not have malicious characters in the URL. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hp2x-6vrm-7j7v

почти 2 года назад

Apache Archiva Reflected Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-27140

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Alternatively, you could configure a HTTP proxy in front of your Archiva instance to only forward requests that do not have malicious characters in the URL. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.4
6%
Низкий
почти 2 года назад
github логотип
GHSA-hp2x-6vrm-7j7v

Apache Archiva Reflected Cross-site Scripting vulnerability

CVSS3: 5.4
6%
Низкий
почти 2 года назад

Уязвимостей на страницу