[SECURITY] CVE-2013-2251: Apache Archiva Remote Command Execution

2014-04-18 Thread Brett Porter
CVE-2013-2251: Apache Archiva Remote Command Execution Severity: Important Vendor: The Apache Software Foundation Versions Affected: - Archiva 1.3 to Continuum 1.3.6 - The unsupported versions Archiva 1.2 to 1.2.2 are also affected. Description: Apache Archiva is affected by a vulnerability in

[SECURITY] CVE-2013-2187: Apache Archiva Cross-Site Scripting vulnerability

2014-04-18 Thread Brett Porter
CVE-2013-2187: Apache Archiva Cross-Site Scripting vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: - Archiva 1.3 to Continuum 1.3.6 - The unsupported versions Archiva 1.2 to 1.2.2 are also affected. Description: A request that included a specially cra

[ANNOUNCE] Apache Archiva 1.3.8 Released

2014-04-18 Thread Brett Porter
The Apache Archiva team would like to announce the release of Archiva 1.3.8. This is primarily a security and bug fix release. All users still on Archiva 1.3.6 or below are advised to upgrade. Users on the newer Archiva 2.0.0 and above are not affected. Archiva is available for download from: *