CVE-2017-5657

HIGH

Apache Archiva < 2.2.1 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).

References (4)

Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
http://archiva.apache.org/security.html#CVE-2017-5657
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98570
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038528

Scores

CVSS v3 8.0
EPSS 0.0014
EPSS Percentile 34.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (6)
apache/archiva < 2.2.1
Apache Software Foundation/Apache Archiva 1.x
Apache Software Foundation/Apache Archiva 2.0.0, 2.0.1
Apache Software Foundation/Apache Archiva 2.1.0, 2.1.1
Apache Software Foundation/Apache Archiva 2.2.0, 2.2.1, 2.2.2
org.apache.archiva/archiva 0 - 2.2.3Maven
Published May 22, 2017
Tracked Since Feb 18, 2026