CVE-2024-27138

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache Archiva that fixes this issue. You are recommended to look into migrating to a different solution, or isolate your instance from any untrusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:*

History

28 May 2025, 19:55

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/03/01/4 - () http://www.openwall.com/lists/oss-security/2024/03/01/4 - Mailing List
References () https://lists.apache.org/thread/070qcpclcb3sqk1hn8j5lvzohp30k1m2 - () https://lists.apache.org/thread/070qcpclcb3sqk1hn8j5lvzohp30k1m2 - Mailing List, Vendor Advisory
First Time Apache archiva
Apache
CPE cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:*

13 Feb 2025, 18:17

Type Values Removed Values Added
Summary (en) ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache Archiva that fixes this issue. You are recommended to look into migrating to a different solution, or isolate your instance from any untrusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer (en) ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache Archiva that fixes this issue. You are recommended to look into migrating to a different solution, or isolate your instance from any untrusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

21 Nov 2024, 09:03

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/03/01/4 - () http://www.openwall.com/lists/oss-security/2024/03/01/4 -
References () https://lists.apache.org/thread/070qcpclcb3sqk1hn8j5lvzohp30k1m2 - () https://lists.apache.org/thread/070qcpclcb3sqk1hn8j5lvzohp30k1m2 -

21 Aug 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

01 May 2024, 17:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/03/01/4 -

21 Mar 2024, 02:52

Type Values Removed Values Added
Summary
  • (es) ** NO SOPORTADO CUANDO SE ASIGNÓ ** Vulnerabilidad de autorización incorrecta en Apache Archiva. Apache Archiva tiene una configuración para deshabilitar el registro de usuarios; sin embargo, esta restricción se puede evitar. Como Apache Archiva ha sido retirado, no esperamos lanzar una versión de Apache Archiva que solucione este problema. Se recomienda considerar la posibilidad de migrar a una solución diferente o aislar su instancia de usuarios que no sean de confianza. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el fabricante

01 Mar 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-01 16:15

Updated : 2025-05-28 19:55


NVD link : CVE-2024-27138

Mitre link : CVE-2024-27138

CVE.ORG link : CVE-2024-27138


JSON object : View

Products Affected

apache

  • archiva
CWE
CWE-863

Incorrect Authorization