Vulnerabilities > Apache > Archiva > 1.4

DATE CVE VULNERABILITY TITLE RISK
2022-11-15 CVE-2022-40308 Unspecified vulnerability in Apache Archiva
If anonymous read enabled, it's possible to read the database file directly without logging in.
network
low complexity
apache
7.5
2022-11-15 CVE-2022-40309 Unspecified vulnerability in Apache Archiva
Users with write permissions to a repository can delete arbitrary directories.
network
low complexity
apache
4.3
2022-05-25 CVE-2022-29405 Unspecified vulnerability in Apache Archiva
In Apache Archiva, any registered user can reset password for any users.
network
low complexity
apache
6.5
2020-06-19 CVE-2020-9495 Injection vulnerability in Apache Archiva
Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection.
network
low complexity
apache CWE-74
5.3
2019-04-30 CVE-2019-0213 Cross-site Scripting vulnerability in Apache Archiva
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e.
network
low complexity
apache CWE-79
6.5
2017-05-22 CVE-2017-5657 Cross-Site Request Forgery (CSRF) vulnerability in Apache Archiva
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks.
network
low complexity
apache CWE-352
8.0