PT-2024-2659 · Apache · Apache Archiva
1Uhrm
·
Published
2024-03-01
·
Updated
2025-05-28
·
CVE-2024-27139
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Archiva versions 2.0.0 and later
Description
The issue is related to an Incorrect Authorization vulnerability in Apache Archiva, allowing an unauthenticated attacker to modify account data, potentially leading to account takeover. This vulnerability can be exploited by a remote attacker to gain access to a user's account.
Recommendations
As the project is retired and no fix will be released, users are recommended to find an alternative to Apache Archiva.
Restrict access to the instance to trusted users to minimize the risk of exploitation.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Archiva