CVE-2022-40308
Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files
If anonymous read enabled, it's possible to read the database file directly without logging in.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
Apache Software Foundation · Apache Archiva¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →