{"api_version":"v1","generated_at":"2026-10-07T03:10:00+00:00","product":{"cve_count":8,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-archiva-0a460fa2657c","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Archiva","next_cursor":null,"observations":[{"affected":"2.0.0 \u2264 *","affected_versions_present":true,"cve_id":"CVE-2024-27138","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27138","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:41:18.332Z","patch_url":"","primary_source":"","published":"2024-03-01T15:41:12.677Z"},{"affected":"2.0.0 \u2264 *","affected_versions_present":true,"cve_id":"CVE-2024-27139","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27139","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-16T20:47:27.623Z","patch_url":"","primary_source":"","published":"2024-03-01T15:40:49.893Z"},{"affected":"2.0.0 \u2264 *","affected_versions_present":true,"cve_id":"CVE-2024-27140","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27140","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:41:19.631Z","patch_url":"","primary_source":"","published":"2024-03-01T15:40:08.456Z"},{"affected":"2.0 < 2.2.10","affected_versions_present":true,"cve_id":"CVE-2023-28158","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28158","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T16:45:40.751Z","patch_url":"","primary_source":"","published":"2023-03-29T12:21:46.932Z"},{"affected":"unspecified \u2264 2.2.8","affected_versions_present":true,"cve_id":"CVE-2022-40309","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-40309","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-30T16:02:30.071Z","patch_url":"","primary_source":"","published":"2022-11-15T00:00:00.000Z"},{"affected":"Apache Archiva \u2264 2.2.8","affected_versions_present":true,"cve_id":"CVE-2022-40308","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-40308","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-30T16:03:13.651Z","patch_url":"","primary_source":"","published":"2022-11-15T00:00:00.000Z"},{"affected":"2.2 \u2264 2.2.7","affected_versions_present":true,"cve_id":"CVE-2022-29405","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-29405","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T06:17:55.082Z","patch_url":"https://archiva.apache.org/docs/2.2.8/release-notes.html","primary_source":"","published":"2022-05-25T07:15:11.000Z"},{"affected":"1.x; 2.0.0, 2.0.1; 2.1.0, 2.1.1; 2.2.0, 2.2.1, 2.2.2","affected_versions_present":true,"cve_id":"CVE-2017-5657","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-5657","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T15:11:48.764Z","patch_url":"http://archiva.apache.org/security.html#CVE-2017-5657","primary_source":"","published":"2017-05-22T18:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
