[SECURITY] CVE-2019-0214: Apache Archiva arbitrary file write and delete on the server

2019-04-30 Thread Martin
CVE-2019-0214: Apache Archiva arbitrary file write and delete on the server

Severity: Medium

Vendor:
The Apache Software Foundation

Versions Affected:
Apache Archiva 2.0.0 - 2.2.3
The unsupported versions 1.x are also affected.  

It is possible to write files to the archiva server at arbitrary locations by 
using the artifact upload mechanism. 
Existing files can be overwritten, if the archiva run user has appropriate 
permission on the filesystem for the target file.

Mitigation:
  It is highly recommended to upgrade to Archiva 2.2.4 or higher, where 
additional validations are implemented to prevent such malicious parameter 
values.
  As intermediate action you may reduce the number of users that are allowed to 
upload to archiva and make sure, that the archiva run user may have only 
  write permission to the directories needed.

References:
http://archiva.apache.org/security.html#CVE-2019-0214

The newest Archiva version can be downloaded from:
http://archiva.apache.org/download.cgi





[SECURITY] CVE-2019-0213: Apache Archiva Stored XSS

2019-04-30 Thread Martin
CVE-2019-0213: Apache Archiva Stored XSS

Severity: Low

Vendor:
The Apache Software Foundation

Versions Affected:
Apache Archiva 2.0.0 - 2.2.3
The unsupported versions 1.x are also affected.  

It may be possible to store malicious XSS code into central configuration 
entries, i.e. the logo URL. 
The vulnerability is considered as minor risk, as only users with admin role 
can change the configuration, or the communication 
between the browser and the Archiva server must be compromised. 

Mitigation:
  All users are recommended to upgrade to Archiva 2.2.4 or higher, 

References:
http://archiva.apache.org/security.html#CVE-2019-0213

The newest Archiva version can be downloaded from:
http://archiva.apache.org/download.cgi





[ANN] Apache Archiva 2.2.4 released

2019-04-30 Thread Martin
The Apache Archiva team is pleased to announce the release of 
   Archiva 2.2.4. 
Archiva is available for download from the web site.

Archiva is an application for managing one or more remote
repositories, including administration, artifact handling, browsing
and searching.

If you have any questions, please consult:

the web site: http://archiva.apache.org/
the archiva-user mailing list: http://archiva.apache.org/mailing-lists.html

Apache Archiva 2.2.4 is a bug fix release.

** As this release contains security fixes, we highly recommend to update to 
the new version. **

See the release notes for more information:
http://archiva.apache.org/docs/2.2.4/release-notes.html

Bugs fixed

[MRM-1972] Stored XSS in Web UI Organization Name

[MRM-1966] Repository-purge not working

[MRM-1958] Purge by retention count deletes files but leaves history on 
website.

[MRM-1929] Repository purge is not reflected in index


Have fun! -- The Apache Archiva Team






Re: Binaries distributable for Archiva 2.2.4

2019-04-30 Thread Martin Stockhammer
Hi,

will be published in the next days.
But it's only a bugfix release. No new features.

Regards

Martin

Am 29. April 2019 21:25:33 MESZ schrieb "Mirabito, Massimo (Max) 
(CDC/DDID/NCHHSTP/OD) (CTR)" :
>Dear All,
>
>We are running Archiva V2.2.3  on Windows. I just noticed that there is
>a 2.2.4 branch on github does anyone know when binaries will be
>available?
>
>Thanks in advance
>max

-- 
This message was sent from mobile phone.