CVE-2023-28158 MEDIUM

CVE-2023-28158: Apache Archiva privilege escalation

Vendor Apache Software Foundation
Product Apache Archiva
Weakness CWE-79 · XSS
Published March 29, 2023
Last update February 13, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

Description

Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.

Key dates

Disclosure timeline

March 29, 2023 CVE published
February 13, 2025 Record updated