CVE-2024-27140: Apache Archiva: reflected XSS

Posted by Arnout Engelen on Mar 01

Severity: moderate

Affected versions:

– Apache Archiva 2.0.0 or later



Improper Neutralization of Input During Web Page Generation (‚Cross-site Scripting‘) vulnerability in Apache Archiva.

This issue affects Apache Archiva: from 2.0.0.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an
alternative or restrict access…
