https://seclists.org/oss-sec/2024/q1/183: CVE-2024-27138: Apache Archiva: disabling user registration is not effective
Published Mar 1, 2024
·Updated
Affected Software
1 affected component
Apache Archiva
Frequently Asked Questions
1
What is the severity of CVE-2024-27138?
CVE-2024-27138 has been assigned a medium severity rating due to its potential for unauthorized user registration.
2
How do I fix CVE-2024-27138?
To mitigate CVE-2024-27138, ensure that user registration is properly disabled in the settings and monitor user activities closely.
3
What systems are affected by CVE-2024-27138?
CVE-2024-27138 affects Apache Archiva installations that have attempted to disable user registration.
4
What is the impact of CVE-2024-27138?
The impact of CVE-2024-27138 includes the risk of unauthorized access if user registration is not effectively disabled.
5
Is there a workaround for CVE-2024-27138?
Currently, the most effective workaround for CVE-2024-27138 is to enhance monitoring and access control until a patch is released.