PT-2024-21669 · Apache · Apache Archiva

Florian Hauser

·

Published

2024-03-01

·

Updated

2025-05-28

·

CVE-2024-27138

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Archiva (affected versions not specified)
Description The issue is related to an Incorrect Authorization vulnerability in Apache Archiva, where a setting to disable user registration can be bypassed. Since Apache Archiva has been retired, no fix is expected to be released for this issue. It is recommended to consider migrating to a different solution or isolating the instance from untrusted users.
Recommendations As a temporary workaround, consider isolating your Apache Archiva instance from any untrusted users. Look into migrating to a different solution to fully resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-27138
GHSA-RV4H-M4WC-V99W

Affected Products

Apache Archiva