CVE-2017-5657 Information

Description

Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site may send an HTML response that performs arbitrary actions on archiva services with the same rights as the active archiva session (e.g. administrator rights).

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Reference

http://archiva.apache.org/security.htmlCVE-2017-5657 http://www.securityfocus.com/bid/98570 http://www.securitytracker.com/id/1038528 https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@3Ccommits.pulsar.apache.org3E

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.0

Share on: