← back
CVE-2022-40308high

Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.3%
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
nono source reports it
If anonymous read enabled, it's possible to read the database file directly without logging in.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N