CVE-2022-40308
Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files
If anonymous read enabled, it's possible to read the database file directly without logging in.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Apache Software Foundation · Apache ArchivaWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →