Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files
CVE-2022-40308
7.5HIGH
What is CVE-2022-40308?
If anonymous read enabled, it's possible to read the database file directly without logging in.
Affected Version(s)
Apache Archiva Apache Archiva <= 2.2.8