CVE-2022-40308

HIGH7.5EPSS 1.1%

Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user

發布日:2022/11/15修改日:2023/11/8

描述

Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files. If anonymous read enabled, it's possible to read the database file directly without logging in.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(5)