Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-0213

In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.3%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 5.5
References
Products affected by CVE-2019-0213
  • Apache » Archiva » Version: 0.9
    cpe:2.3:a:apache:archiva:0.9
  • Apache » Archiva » Version: 1.0
    cpe:2.3:a:apache:archiva:1.0
  • Apache » Archiva » Version: 1.0.1
    cpe:2.3:a:apache:archiva:1.0.1
  • Apache » Archiva » Version: 1.0.2
    cpe:2.3:a:apache:archiva:1.0.2
  • Apache » Archiva » Version: 1.1
    cpe:2.3:a:apache:archiva:1.1
  • Apache » Archiva » Version: 1.1.1
    cpe:2.3:a:apache:archiva:1.1.1
  • Apache » Archiva » Version: 1.1.2
    cpe:2.3:a:apache:archiva:1.1.2
  • Apache » Archiva » Version: 1.1.3
    cpe:2.3:a:apache:archiva:1.1.3
  • Apache » Archiva » Version: 1.1.4
    cpe:2.3:a:apache:archiva:1.1.4
  • Apache » Archiva » Version: 1.2
    cpe:2.3:a:apache:archiva:1.2
  • Apache » Archiva » Version: 1.2.1
    cpe:2.3:a:apache:archiva:1.2.1
  • Apache » Archiva » Version: 1.2.2
    cpe:2.3:a:apache:archiva:1.2.2
  • Apache » Archiva » Version: 1.3
    cpe:2.3:a:apache:archiva:1.3
  • Apache » Archiva » Version: 1.3.1
    cpe:2.3:a:apache:archiva:1.3.1
  • Apache » Archiva » Version: 1.3.2
    cpe:2.3:a:apache:archiva:1.3.2
  • Apache » Archiva » Version: 1.3.3
    cpe:2.3:a:apache:archiva:1.3.3
  • Apache » Archiva » Version: 1.3.4
    cpe:2.3:a:apache:archiva:1.3.4
  • Apache » Archiva » Version: 1.3.5
    cpe:2.3:a:apache:archiva:1.3.5
  • Apache » Archiva » Version: 1.3.6
    cpe:2.3:a:apache:archiva:1.3.6
  • Apache » Archiva » Version: 1.3.8
    cpe:2.3:a:apache:archiva:1.3.8
  • Apache » Archiva » Version: 1.3.9
    cpe:2.3:a:apache:archiva:1.3.9
  • Apache » Archiva » Version: 1.4
    cpe:2.3:a:apache:archiva:1.4
  • Apache » Archiva » Version: 2.0.0
    cpe:2.3:a:apache:archiva:2.0.0
  • Apache » Archiva » Version: 2.0.1
    cpe:2.3:a:apache:archiva:2.0.1
  • Apache » Archiva » Version: 2.1.0
    cpe:2.3:a:apache:archiva:2.1.0
  • Apache » Archiva » Version: 2.1.1
    cpe:2.3:a:apache:archiva:2.1.1
  • Apache » Archiva » Version: 2.2.0
    cpe:2.3:a:apache:archiva:2.2.0
  • Apache » Archiva » Version: 2.2.1
    cpe:2.3:a:apache:archiva:2.2.1
  • Apache » Archiva » Version: 2.2.2
    cpe:2.3:a:apache:archiva:2.2.2
  • Apache » Archiva » Version: 2.2.3
    cpe:2.3:a:apache:archiva:2.2.3


Contact Us

Shodan ® - All rights reserved