PT-2024-21671 · Apache · Apache Archiva

Ben Tullis

+6

·

Published

2024-03-01

·

Updated

2025-05-28

·

CVE-2024-27140

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Archiva versions 2.0.0 and later
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting. This affects Apache Archiva, a product that is no longer supported by its maintainer. As a result, no fix is planned for this issue. Users are advised to find an alternative or restrict access to the instance to trusted users. An additional mitigation measure is to configure an HTTP proxy in front of the Archiva instance to filter out requests with malicious characters in the URL.
Recommendations For Apache Archiva versions 2.0.0 and later, consider the following:
  • Find an alternative to Apache Archiva.
  • Restrict access to the instance to trusted users.
  • Configure an HTTP proxy in front of the Archiva instance to only forward requests that do not have malicious characters in the URL. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-27140
GHSA-HP2X-6VRM-7J7V

Affected Products

Apache Archiva