CVE-2019-0213: Apache Archiva Stored XSS
The Apache Software Foundation
Apache Archiva 2.0.0 - 2.2.3
The unsupported versions 1.x are also affected.
It may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL.
The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication
between the browser and the Archiva server must be compromised.
All users are recommended to upgrade to Archiva 2.2.4 or higher,
The newest Archiva version can be downloaded from: