GHSA-hp2x-6vrm-7j7v
Dashboard / Vulnerabilities / GHSA-hp2x-6vrm-7j7v
Summary: Apache Archiva Reflected Cross-site Scripting vulnerability
Details: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Alternatively, you could configure a HTTP proxy in front of your Archiva instance to only forward requests that do not have malicious characters in the URL. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References: https://nvd.nist.gov/vuln/detail/CVE-2024-27140, https://attic.apache.org/projects/archiva.html, https://github.com/apache/archiva, https://lists.apache.org/thread/xrn6nt904ozh3jym60c3f5hj2fb75pjy, http://www.openwall.com/lists/oss-security/2024/03/01/2
Affected packages
Package
Name: org.apache.archiva:archiva-common
Purl: pkg:maven/org.apache.archiva/archiva-common
Affected ranges
Type: ECOSYSTEM
Events:
