PT-2023-2336 · Apache · Apache Archiva
Sandr0
·
Publicado
2023-03-29
·
Atualizado
2023-04-18
·
CVE-2023-28158
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Archiva (affected versions not specified)
Description
The issue is related to privilege escalation via stored cross-site scripting (XSS) using the file upload service to upload malicious content. This can be exploited by authenticated users who can create directory names to inject XSS content and gain privileges, such as admin user. The vulnerability allows a remote attacker to perform cross-site scripting attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the file upload service until a patch is available. Restrict access to the directory creation feature to minimize the risk of exploitation. Avoid using the file upload service to upload unverified content until the issue is resolved.
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Archiva