https://seclists.org/oss-sec/2024/q1/182: CVE-2024-27139: Apache Archiva: incorrect authentication potentially leading to account takeover
Published Mar 1, 2024
·Updated
Affected Software
1 affected component
Apache Archiva
Frequently Asked Questions
1
What is the severity of CVE-2024-27139?
The severity of CVE-2024-27139 is classified as high due to the potential for account takeover.
2
How do I fix CVE-2024-27139?
To fix CVE-2024-27139, update to the fixed version of Apache Archiva as released by the developers.
3
What vulnerability does CVE-2024-27139 describe?
CVE-2024-27139 describes a vulnerability in Apache Archiva that allows for incorrect authentication, which could lead to account takeover.
4
Who is affected by CVE-2024-27139?
Users of Apache Archiva who rely on its authentication mechanisms may be affected by CVE-2024-27139.
5
When was CVE-2024-27139 published?
CVE-2024-27139 was published on March 1, 2024.