U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-27138

Change History

New CVE Received by NIST 3/01/2024 11:15:45 AM

Action Type Old Value New Value
Added CWE

								
							
							
						
Apache Software Foundation CWE-863
Added Description

								
							
							
						
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva.

Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache Archiva that fixes this issue. You are recommended to look into migrating to a different solution, or isolate your instance from any untrusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Added Reference

								
							
							
						
Apache Software Foundation https://lists.apache.org/thread/070qcpclcb3sqk1hn8j5lvzohp30k1m2 [No types assigned]