Lucene search

K
osvGoogleOSV:GHSA-RV4H-M4WC-V99W
HistoryMar 01, 2024 - 6:30 p.m.

Apache Archiva Incorrect Authorization vulnerability

2024-03-0118:30:23
Google
osv.dev
8
apache archiva
incorrect authorization
user registration
bypass
no fix
migration
isolate
untrusted users

AI Score

7

Confidence

High

EPSS

0

Percentile

9.0%

UNSUPPORTED WHEN ASSIGNED Incorrect Authorization vulnerability in Apache Archiva.

Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache Archiva that fixes this issue. You are recommended to look into migrating to a different solution, or isolate your instance from any untrusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer

AI Score

7

Confidence

High

EPSS

0

Percentile

9.0%

Related for OSV:GHSA-RV4H-M4WC-V99W