First published: Tue Apr 22 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to the home page.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Archiva | =1.2 | |
Apache Archiva | =1.2.1 | |
Apache Archiva | =1.2.2 | |
Apache Archiva | =1.3 | |
Apache Archiva | =1.3.1 | |
Apache Archiva | =1.3.2 | |
Apache Archiva | =1.3.3 | |
Apache Archiva | =1.3.4 | |
Apache Archiva | =1.3.5 | |
Apache Archiva | =1.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2187 has a medium severity rating due to its cross-site scripting nature.
To fix CVE-2013-2187, upgrade Apache Archiva to version 1.3.8 or later.
CVE-2013-2187 affects Apache Archiva versions 1.2 through 1.2.2 and versions 1.3 before 1.3.8.
CVE-2013-2187 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2013-2187 can be exploited remotely to inject arbitrary web scripts or HTML.