|
Message-ID: <2048242.ks9QkeOCCd@golgafrichnam> Date: Tue, 30 Apr 2019 17:18:58 +0200 From: Martin <martin_s@...che.org> To: users@...hiva.apache.org, users@...en.apache.org, announce@...che.org Cc: oss-security@...ts.openwall.com, bugtraq@...urityfocus.com Subject: [SECURITY] CVE-2019-0213: Apache Archiva Stored XSS CVE-2019-0213: Apache Archiva Stored XSS Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Archiva 2.0.0 - 2.2.3 The unsupported versions 1.x are also affected. It may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised. Mitigation: All users are recommended to upgrade to Archiva 2.2.4 or higher, References: http://archiva.apache.org/security.html#CVE-2019-0213 The newest Archiva version can be downloaded from: http://archiva.apache.org/download.cgi
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.