CVE-2022-40308
published 2022-11-15CVE-2022-40308: If anonymous read enabled, it's possible to read the database file directly without logging in.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.19%
64.5th percentile
If anonymous read enabled, it's possible to read the database file directly without logging in.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | archiva | < 2.2.9 | 2.2.9 |
| apache_software_foundation | apache_archiva | Apache Archiva – 2.2.8 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
osv·2022-11-15
CVE-2022-40308 [HIGH] Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files. If anonymous read enabled, it's possible to read the database file directly without logging in.
GHSA
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
ghsa·2022-11-15
CVE-2022-40308 [HIGH] CWE-200 Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files. If anonymous read enabled, it's possible to read the database file directly without logging in.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-15
Published