CVE-2024-27139: Apache Archiva: incorrect authentication potentially leading to account takeover
UNSUPPORTED WHEN ASSIGNED
Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated attacker to modify account data, potentially leading to account takeover.
This issue affects Apache Archiva: from 2.0.0.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27139?
CVE-2024-27139 is classified as a critical vulnerability due to its potential to allow account takeover by an unauthenticated attacker.
How do I fix CVE-2024-27139?
To mitigate CVE-2024-27139, upgrade Apache Archiva to a version later than 2.2.10.
What software is affected by CVE-2024-27139?
CVE-2024-27139 affects Apache Archiva versions from 2.0.0 up to 2.2.10.
What type of vulnerability is CVE-2024-27139?
CVE-2024-27139 is an incorrect authorization vulnerability that allows unauthorized access to modify account data.
Can I exploit CVE-2024-27139 without authentication?
Yes, CVE-2024-27139 can be exploited by an unauthenticated attacker.