Security Advisory

CVE-2017-5657

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-05-22 18:00:00
Last updated 2024-08-05 15:11:48
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).