[MAVEN:GHSA-JXGM-9F58-W4XP] Improper Input Validation in Apache Archiva

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.

Package Affected Version
pkg:maven/org.apache.archiva/archiva >= 2.2.0, < 2.2.4
Package Fixed Version
pkg:maven/org.apache.archiva/archiva = 2.2.4
ID
MAVEN:GHSA-JXGM-9F58-W4XP
Severity
moderate
URL
https://github.com/advisories/GHSA-jxgm-9f58-w4xp
Published
2019-05-14T04:00:21
(5 years ago)
Modified
2023-02-01T05:01:40
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.archiva/archiva org.apache.archiva archiva >= 2.2.0 < 2.2.4
Fixed pkg:maven/org.apache.archiva/archiva org.apache.archiva archiva = 2.2.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...