Vulnerability CVE-2024-27138


Published: 2024-03-01

Description:
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva.

Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache Archiva that fixes this issue. You are recommended to look into migrating to a different solution, or isolate your instance from any untrusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Type:

CWE-863

(Incorrect Authorization)

 References:
https://lists.apache.org/thread/070qcpclcb3sqk1hn8j5lvzohp30k1m2

Copyright 2024, cxsecurity.com

 

Back to Top