CVE-2013-2187: XSS
Published Apr 22, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to the home page.
Affected Software
10 affected components
Apache Archiva=1.2
Apache Archiva=1.2.1
Apache Archiva=1.2.2
Apache Archiva=1.3
Apache Archiva=1.3.1
Apache Archiva=1.3.2
Apache Archiva=1.3.3
Apache Archiva=1.3.4
Apache Archiva=1.3.5
Apache Archiva=1.3.6
Remediation
Patch Available
Event History
Apr 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:23 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-2187?
CVE-2013-2187 has a medium severity rating due to its cross-site scripting nature.
2
How do I fix CVE-2013-2187?
To fix CVE-2013-2187, upgrade Apache Archiva to version 1.3.8 or later.
3
What versions of Apache Archiva are affected by CVE-2013-2187?
CVE-2013-2187 affects Apache Archiva versions 1.2 through 1.2.2 and versions 1.3 before 1.3.8.
4
What type of vulnerability is CVE-2013-2187?
CVE-2013-2187 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2013-2187 be exploited remotely?
Yes, CVE-2013-2187 can be exploited remotely to inject arbitrary web scripts or HTML.