CVE-2019-0213

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-0213
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-0213.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-0213
Aliases
Published
2019-04-30T22:29:00Z
Modified
2024-09-03T02:20:54.269039Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised.

References

Affected packages

Git / github.com/apache/archiva

Affected ranges

Type
GIT
Repo
https://github.com/apache/archiva
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

archiva-2.*

archiva-2.1.0
archiva-2.1.1
archiva-2.2.0
archiva-2.2.1
archiva-2.2.2
archiva-2.2.3