Apache Archiva Multiple CSRF vulnerability

2011.06.04
Credit: Deng Ching
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-352


CVSS Base Score: 6.8/10
Impact Subscore: 6.4/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

CVE-2011-1026: Apache Archiva Multiple CSRF vulnerability Severity: High Vendor: The Apache Software Foundation Versions Affected: Archiva 1.3.0 - 1.3.4 The unsupported versions Archiva 1.0 - 1.2.2 are also affected. Description: An attacker can build a simple html page containing a hidden Image tag (eg:<img src=vulnurl width=0 height=0 />) and entice theadministrator to access the page. Mitigation: Archiva 1.3.4 and earlier users should upgrade to 1.3.5 Credit: This issue was discovered by Riyaz Ahemed Walikar of Microland Ltd., India References: http://archiva.apache.org/security.html Thanks, The Apache Archiva Team

References:

http://xforce.iss.net/xforce/xfdb/67671
http://www.securityfocus.com/bid/48015
http://www.securityfocus.com/archive/1/archive/1/518168/100/0/threaded
http://secunia.com/advisories/44693
http://archives.neohapsis.com/archives/fulldisclosure/2011-05/0532.html
http://archiva.apache.org/security.html
http://archiva.apache.org/docs/1.3.5/release-notes.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top