CVE-2022-40309: Apache Archiva prior to 2.2.9 allows an authenticated user to delete arbitrary directories
Published Nov 15, 2022
·Updated
Users with write permissions to a repository can delete arbitrary directories.
Affected Software
1 affected component
Apache Archiva<2.2.9
Event History
Nov 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40309?
CVE-2022-40309 has been assigned a medium severity rating due to the potential for unauthorized deletion of arbitrary directories.
2
How do I fix CVE-2022-40309?
To fix CVE-2022-40309, upgrade to Apache Archiva version 2.2.9 or higher.
3
Who is affected by CVE-2022-40309?
Any user with write permissions on an Apache Archiva repository is affected by CVE-2022-40309.
4
What functionality does CVE-2022-40309 compromise?
CVE-2022-40309 compromises the ability to prevent the deletion of arbitrary directories by users with write access.
5
Is there a workaround for CVE-2022-40309?
Currently, there are no known workarounds for CVE-2022-40309 other than applying the available security updates.