
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-28158 is a vulnerability discovered in Apache Archiva affecting versions from 2.0 up to (excluding) 2.2.10. The vulnerability was initially reported on March 29, 2023, and involves a privilege escalation vulnerability through stored Cross-Site Scripting (XSS) in the file upload service (NVD, CVE).
The vulnerability is classified as a stored XSS vulnerability (CWE-79) that can be exploited through the file upload service. It received a CVSS v3.1 base score of 5.4 (Medium) from NIST and 6.5 (Medium) from Apache Software Foundation. The attack vector is network-based (AV:N) with low attack complexity (AC:L), requiring low privileges (PR:L) and user interaction (UI:R) (NVD).
When successfully exploited, this vulnerability allows authenticated users to escalate their privileges to administrative level by creating directory names containing malicious XSS content. The vulnerability affects confidentiality and integrity with low impact, while availability impact varies between none to low according to different assessments (NVD).
The vulnerability affects Apache Archiva versions from 2.0 up to version 2.2.10. Users are advised to upgrade to a patched version when available (NVD).
The security community has noted that the initial disclosure lacked sufficient details about affected versions and fix information, as highlighted in discussions on the oss-security mailing list (Openwall).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."