Описание
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files. If anonymous read enabled, it's possible to read the database file directly without logging in.
Пакеты
Наименование
org.apache.archiva:archiva-common
maven
Затронутые версииВерсия исправления
< 2.2.9
2.2.9
Связанные уязвимости
CVSS3: 7.5
nvd
около 3 лет назад
If anonymous read enabled, it's possible to read the database file directly without logging in.