CVE-2024-27140
Java vulnerability analysis and mitigation

Overview

A Cross-site Scripting (XSS) vulnerability has been identified in Apache Archiva, tracked as CVE-2024-27140. The vulnerability affects Apache Archiva versions 2.0.0 and later. This is a reflected XSS vulnerability that stems from improper neutralization of input during web page generation. The issue was discovered by multiple security researchers including Sandro Bauer, Ben Tullis, Scott Bassett, and L0ne1y (OSS Security).

Technical details

The vulnerability is classified as an Improper Neutralization of Input During Web Page Generation (CWE-79) issue. According to the CISA Automated Directive Program assessment, it has received a CVSS v3.1 base score of 5.4 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N (NVD).

Impact

The vulnerability could allow attackers to execute cross-site scripting attacks against users of the affected Apache Archiva installations. As this is a reflected XSS vulnerability, it could potentially lead to the theft of user session tokens, cookies, or other sensitive information handled by the affected application (OSS Security).

Exploitability

The vulnerability requires low attack complexity and user interaction for successful exploitation. An attacker would need to craft specific URLs containing malicious characters to trigger the XSS condition (NVD).

Mitigation and workarounds

As Apache Archiva is now retired, no official patch will be released to address this vulnerability. Users are recommended to either find an alternative solution or implement one of two workarounds: 1) restrict access to the Archiva instance to trusted users only, or 2) configure an HTTP proxy in front of the Archiva instance to filter requests containing malicious characters in the URL (OSS Security).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76904CRITICAL9.8
  • Java logoJava
  • org.geotools.jdbc:gt-jdbc-postgis
NoYesAug 21, 2026
GHSA-mqjf-5f49-2fjhCRITICAL9.8
  • Java logoJava
  • org.geotools:gt-jdbc-postgis
NoYesAug 21, 2026
CVE-2026-54049HIGH8.7
  • Java logoJava
  • org.sakaiproject.conversations:sakai-conversations-impl
NoNoAug 24, 2026
CVE-2026-63202HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-54050MEDIUM6.5
  • Java logoJava
  • org.sakaiproject.profile2:profile2-api
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management