CVE-2024-27140: Apache Archiva: reflected XSS
UNSUPPORTED WHEN ASSIGNED
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva.
This issue affects Apache Archiva: from 2.0.0.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Alternatively, you could configure a HTTP proxy in front of your Archiva instance to only forward requests that do not have malicious characters in the URL.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27140?
CVE-2024-27140 is classified as a Cross-site Scripting (XSS) vulnerability, which can have a significant impact on web application security.
How do I fix CVE-2024-27140?
There is no fix for CVE-2024-27140 as Apache Archiva is retired and unsupported.
Which versions of Apache Archiva are affected by CVE-2024-27140?
CVE-2024-27140 affects Apache Archiva versions from 2.0.0 to 2.2.10.
What kind of vulnerability is CVE-2024-27140?
CVE-2024-27140 is a Cross-site Scripting vulnerability due to improper neutralization of input.
Is there a workaround for CVE-2024-27140?
Since CVE-2024-27140 is associated with an unsupported software version, no official workarounds are available.