CVE-2022-40308

HIGH7.5EPSS 1.1%

Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user

Published: 11/15/2022Modified: 11/8/2023
Also known as:GHSA-463w-hxfv-g9f6

Description

Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files. If anonymous read enabled, it's possible to read the database file directly without logging in.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (5)