PT-2024-2659 · Apache · Apache Archiva

1Uhrm

·

Published

2024-03-01

·

Updated

2025-05-28

·

CVE-2024-27139

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Archiva versions 2.0.0 and later
Description The issue is related to an Incorrect Authorization vulnerability in Apache Archiva, allowing an unauthenticated attacker to modify account data, potentially leading to account takeover. This vulnerability can be exploited by a remote attacker to gain access to a user's account.
Recommendations As the project is retired and no fix will be released, users are recommended to find an alternative to Apache Archiva. Restrict access to the instance to trusted users to minimize the risk of exploitation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-02726
CVE-2024-27139
GHSA-H595-VWHC-3XWX

Affected Products

Apache Archiva