VulnerabilityModified
CVE-2019-0213
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL.
MEDIUM 6.5EPSS 4.84%
Does this matter?
Lower severity and a low EPSS score (4.84%). Track it; it rarely justifies an emergency change on its own.
Description
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 4.84% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/archiva
- Source
- security@apache.org
References
- http://archiva.apache.org/security.html#CVE-2019-0213Vendor Advisory
- http://packetstormsecurity.com/files/152681/Apache-Archiva-2.2.3-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/04/30/7Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108123Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/0397ddbd17b5257cc1746b31a07294a87221c5ca24e5d19d390e28f3%40%3Cusers.archiva.apache.org%3E
- https://lists.apache.org/thread.html/7bcea134c3d6fa72cdc1052922ac0914f399f63f4690b7937b80127d%40%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/ada0052409d8a4a8c4eb2c7fd6b9cd9423bc753d5fce87eb826662fb%40%3Cissues.archiva.apache.org%3E
- https://lists.apache.org/thread.html/c358754a35473a61477f9d487870581a0dd7054ff95974628fa09f97%40%3Cusers.maven.apache.org%3E
- https://seclists.org/bugtraq/2019/Apr/47Mailing List, Third Party Advisory
- http://archiva.apache.org/security.html#CVE-2019-0213Vendor Advisory
- http://packetstormsecurity.com/files/152681/Apache-Archiva-2.2.3-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/04/30/7Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108123Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/0397ddbd17b5257cc1746b31a07294a87221c5ca24e5d19d390e28f3%40%3Cusers.archiva.apache.org%3E
- https://lists.apache.org/thread.html/7bcea134c3d6fa72cdc1052922ac0914f399f63f4690b7937b80127d%40%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/ada0052409d8a4a8c4eb2c7fd6b9cd9423bc753d5fce87eb826662fb%40%3Cissues.archiva.apache.org%3E
- https://lists.apache.org/thread.html/c358754a35473a61477f9d487870581a0dd7054ff95974628fa09f97%40%3Cusers.maven.apache.org%3E
- https://seclists.org/bugtraq/2019/Apr/47Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.