First published: Tue Nov 15 2022(Updated: )
Users with write permissions to a repository can delete arbitrary directories.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Archiva | <2.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40309 has been assigned a medium severity rating due to the potential for unauthorized deletion of arbitrary directories.
To fix CVE-2022-40309, upgrade to Apache Archiva version 2.2.9 or higher.
Any user with write permissions on an Apache Archiva repository is affected by CVE-2022-40309.
CVE-2022-40309 compromises the ability to prevent the deletion of arbitrary directories by users with write access.
Currently, there are no known workarounds for CVE-2022-40309 other than applying the available security updates.