cbcvebase.
CVE-2022-40308
published 2022-11-15

CVE-2022-40308: If anonymous read enabled, it's possible to read the database file directly without logging in.

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
If anonymous read enabled, it's possible to read the database file directly without logging in.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachearchiva< 2.2.92.2.9
apache_software_foundationapache_archivaApache Archiva – 2.2.8