Severity
7.5HIGH
EPSS
1.1%
top 22.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

If anonymous read enabled, it's possible to read the database file directly without logging in.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/archiva< 2.2.9
CVEListV5apache_software_foundation/apache_archivaApache Archiva2.2.8

🔴Vulnerability Details

3
OSV
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user2022-11-15
GHSA
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user2022-11-15
CVEList
Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files2022-11-15
CVE-2022-40308 (HIGH CVSS 7.5) | If anonymous read enabled | cvebase.io