Incorrect Authorization vulnerability in Apache Archiva
CVE-2024-27138

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
1 March 2024

Summary

An Incorrect Authorization vulnerability exists in Apache Archiva, allowing unauthorized access even when user registration is disabled. This vulnerability arises due to the software's retirement and lack of updates or support from the maintainer. Users are advised to consider migrating to a different solution or implementing isolation measures to protect their instances from untrusted access.

Affected Version(s)

Apache Archiva 2.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Florian Hauser, @frycos
.