PT-2024-21669 · Apache · Apache Archiva
Florian Hauser
·
Published
2024-03-01
·
Updated
2025-05-28
·
CVE-2024-27138
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Archiva (affected versions not specified)
Description
The issue is related to an Incorrect Authorization vulnerability in Apache Archiva, where a setting to disable user registration can be bypassed. Since Apache Archiva has been retired, no fix is expected to be released for this issue. It is recommended to consider migrating to a different solution or isolating the instance from untrusted users.
Recommendations
As a temporary workaround, consider isolating your Apache Archiva instance from any untrusted users.
Look into migrating to a different solution to fully resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Archiva