PT-2017-16651 · Apache · Apache Archiva

Publicado

2017-05-22

·

Atualizado

2022-05-14

·

CVE-2017-5657

CVSS v3.1

8.0

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Archiva (affected versions not specified)
Description The issue concerns several REST service endpoints of Apache Archiva that are not protected against Cross Site Request Forgery (CSRF) attacks. This means a malicious site, opened in the same browser as the Archiva site, can send an HTML response that performs arbitrary actions on Archiva services with the same rights as the active Archiva session, potentially including administrator rights.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5657
GHSA-HF4P-MHC8-X2GP

Produtos afetados

Apache Archiva