Incorrect Authorization vulnerability in Apache Archiva
CVE-2024-27138
7.5HIGH
Summary
An Incorrect Authorization vulnerability exists in Apache Archiva, allowing unauthorized access even when user registration is disabled. This vulnerability arises due to the software's retirement and lack of updates or support from the maintainer. Users are advised to consider migrating to a different solution or implementing isolation measures to protect their instances from untrusted access.
Affected Version(s)
Apache Archiva 2.0.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Florian Hauser, @frycos