CVE-2022-40308
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
7.5
HIGH
CVSS 3.1
EPSS 0.60%
Description
Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files. If anonymous read enabled, it's possible to read the database file directly without logging in.
How to fix CVE-2022-40308
To remediate CVE-2022-40308, upgrade the affected package to a fixed version below.
- Maven/org.apache.archiva:archiva-common—upgrade to 2.2.9 or later
Is CVE-2022-40308 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.2.9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |