Apache / Archiva
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-27138 | Apache Archiva: disabling user registration is not effective | HIGH | 8.7 | Mar 1, 2024 |
| CVE-2024-27139 | Apache Archiva: incorrect authentication potentially leading to account takeover | HIGH | 8.7 | Mar 1, 2024 |
| CVE-2024-27140 | Apache Archiva: reflected XSS | MEDIUM | 5.4 | Mar 1, 2024 |
| CVE-2023-28158 | Apache Archiva privilege escalation | MEDIUM | 6.5 | Mar 29, 2023 |
| CVE-2022-40309 | Apache Archiva prior to 2.2.9 allows an authenticated user to delete arbitrary directories | MEDIUM | 4.3 | Nov 15, 2022 |
| CVE-2022-40308 | Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files | HIGH | 7.5 | Nov 15, 2022 |
| CVE-2022-29405 | Apache Archiva Arbitrary user password reset vulnerability | MEDIUM | 6.5 | May 25, 2022 |
| CVE-2020-9495 | Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by… | MEDIUM | 5.3 | Jun 19, 2020 |
| CVE-2019-0214 | In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing fi… | MEDIUM | 6.5 | Apr 30, 2019 |
| CVE-2019-0213 | In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is cons… | MEDIUM | 6.5 | Apr 30, 2019 |
| CVE-2017-5657 | Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same brows… | HIGH | 8.0 | May 22, 2017 |
| CVE-2016-5005 | Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML… | MEDIUM | 4.8 | Jul 28, 2016 |
| CVE-2016-4469 | Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of administr… | HIGH | 8.8 | Jul 28, 2016 |
| CVE-2013-2187 | Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTM… | MEDIUM | 4.3 | Apr 22, 2014 |
| CVE-2013-2251 KEV | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or… | CRITICAL | 9.8 | Jul 18, 2013 |
| CVE-2011-1077 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web… | MEDIUM | 4.3 | Jun 2, 2011 |
| CVE-2011-1026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the au… | MEDIUM | 6.8 | Jun 2, 2011 |
| CVE-2011-0533 | Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 a… | MEDIUM | 4.3 | Feb 17, 2011 |
| CVE-2010-4408 | Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the tim… | MEDIUM | 6.9 | Dec 6, 2010 |
| CVE-2010-3449 | Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and… | MEDIUM | 6.8 | Dec 6, 2010 |
Showing 1 to 20 of 20 CVEs