Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-40308

25
FAUCET Score

CVE-2022-40308 is a high-severity vulnerability affecting Apache Archiva, allowing unauthenticated attackers to directly read the database file if anonymous read is enabled. With a CVSS score of 7.5, this network-exploitable flaw requires no user interaction and could lead to significant data confidentiality breaches. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for unauthorized data access warrants attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.2.9CPE matchmatch criteria
cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.19%
Probability of exploitation in next 30 days
EPSS Percentile
64.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0119 is in the 43rd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: org.apache.archiva:archiva-commonFixed in: 2.2.9

Vendor Advisories (1)

mavenGHSA-463w-hxfv-g9f6high

Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user

Nov 15, 2022

References

lists.apache.org / thread/x01pnn0jjsw512cscxsbxzrjmz64n4cc
Issue TrackingMailing ListVendor Advisory
openwall.com / lists/oss-security/2022/11/15/2
Mailing ListThird Party Advisory