vendor:
Apache Archiva
by:
Anatolia Security
7.5
CVSS
HIGH
Cross-site Request Forgery
352
CWE
Product Name: Apache Archiva
Affected Version From: Archiva 1.0
Affected Version To: Archiva 1.3.1
Patch Exists: YES
Related CWE: CVE-2010-3449
CPE: cpe:2.3:a:apache:archiva:1.0:*:*:*:*:*:*:*
Platforms Tested:
2010
Apache Archiva Cross-site Request Forgery Vulnerability
Apache Archiva affects from Cross-site Request Forgery. Application don't check which form sends credentials. Technically, attacker can create a specially crafted page and force archiva administrators to view it and change their credentials. For prevention from CSRF vulnerabilities, application needs anti-csrf token, captcha and asking old password for action like change password. Vulnerability patched by the Apache Archiva Team.
Mitigation:
Vulnerability patched by the Apache Archiva Team.