CVE-2024-27138: Apache Archiva: disabling user registration is not effective
UNSUPPORTED WHEN ASSIGNED Incorrect Authorization vulnerability in Apache Archiva.
Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache Archiva that fixes this issue. You are recommended to look into migrating to a different solution, or isolate your instance from any untrusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27138?
CVE-2024-27138 presents an incorrect authorization vulnerability in Apache Archiva, which may pose significant security risks.
How do I fix CVE-2024-27138?
Since Apache Archiva is unsupported and retired, there is no patch or fix available for CVE-2024-27138.
Which versions of Apache Archiva are affected by CVE-2024-27138?
CVE-2024-27138 affects Apache Archiva versions up to and including 2.2.10.
What is the consequence of the vulnerability identified in CVE-2024-27138?
The consequence of CVE-2024-27138 is that the user registration restriction can be bypassed, allowing unauthorized access.
Is there a workaround for CVE-2024-27138 since Archiva is unsupported?
There are no official workarounds for CVE-2024-27138 due to the retirement of Apache Archiva.