Known vulnerabilities in Apache Archiva
Vendor:
Apache Foundation
Software:
Apache Archiva
Software CPE:
cpe:2.3:a:apache_foundation:apache_archiva:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU86999 - Improper Access Control CVE-2024-27138 |
CWE-284 | Medium | - | 04.03.2024 |
SB2024030420 |
||
| #VU86998 - Improper Authentication CVE-2024-27139 |
CWE-287 | High | - | 04.03.2024 |
SB2024030420 |
||
| #VU86997 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-27140 |
CWE-79 | Medium | - | 04.03.2024 |
SB2024030420 |
||
| #VU74218 - Unrestricted Upload of File with Dangerous Type CVE-2023-28158 |
CWE-434 | Low | 2.2.10 | 30.03.2023 |
SB2023033064 |
||
| #VU63851 - Security Features CVE-2022-29405 |
CWE-254 | Medium | 2.2.8 | 31.05.2022 |
SB2022053108 |
||
| #VU58816 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44228 |
CWE-94 | Critical | 2.2.6 | 10.12.2021 |
SB2021121003 SB2021121101 SB2021121201 and 338 more |