Uploaded image for project: 'Continuum'
  1. Continuum
  2. CONTINUUM-2603

CSRF vulnerability - Continuum doesn't check which form sends credentials

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • None
    • 1.3.7, 1.4.1
    • Security
    • None

    Description

      As reported by Anatolia Security Research Group, Apache Archiva doesn't check which form sends credentials. An attacker can create a specially crafted page and force archiva administrators to view it and change their credentials.

      Vulnerability reference key: [CVE-2010-3449] Apache Archiva CSRF Vulnerability

      Attachments

        Activity

          People

            brett Brett Porter
            oching Maria Odea B. Ching
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: