Apache Archiva privilege escalation
Vulnerability Description
Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-28158
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- sandr0 (sandr0.xyz)
References
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →