Description
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).
References (4)
Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
http://archiva.apache.org/security.html#CVE-2017-5657
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/98570
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1038528
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
Scores
CVSS v3
8.0
EPSS
0.0014
EPSS Percentile
34.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (6)
apache/archiva
< 2.2.1
Apache Software Foundation/Apache Archiva
1.x
Apache Software Foundation/Apache Archiva
2.0.0, 2.0.1
Apache Software Foundation/Apache Archiva
2.1.0, 2.1.1
Apache Software Foundation/Apache Archiva
2.2.0, 2.2.1, 2.2.2
org.apache.archiva/archiva
0 - 2.2.3Maven
Published
May 22, 2017
Tracked Since
Feb 18, 2026