CVE-2022-40308
HIGH7.5EPSS 1.1%Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
Published: 11/15/2022Modified: 11/8/2023
Also known as:GHSA-463w-hxfv-g9f6
Description
Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files. If anonymous read enabled, it's possible to read the database file directly without logging in.
Affected packages (1)
- Maven/org.apache.archiva:archiva-commonfrom 0, < 2.2.9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |