Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45781
HistoryMar 06, 2024 - 9:14 a.m.

Incorrect Authorization

2024-03-0609:14:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
org.apache.archiva
archiva
incorrect authorization
vulnerability
unauthorized registration
access restriction bypass
software

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

org.apache.archiva:archiva is vulnerable to Incorrect Authorization. The vulnerability is due to unauthorized users being able to register when registration is set to be disabled. This flaw potentially leads to an Access Restriction Bypass.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%