PT-2017-16651 · Apache · Apache Archiva

Published

2017-05-22

·

Updated

2022-05-14

·

CVE-2017-5657

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Archiva (affected versions not specified)
Description The issue concerns several REST service endpoints of Apache Archiva that are not protected against Cross Site Request Forgery (CSRF) attacks. This means a malicious site, opened in the same browser as the Archiva site, can send an HTML response that performs arbitrary actions on Archiva services with the same rights as the active Archiva session, potentially including administrator rights.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5657
GHSA-HF4P-MHC8-X2GP

Affected Products

Apache Archiva