Authentication Bypass in Apache Archiva by The Apache Software Foundation
CVE-2010-4408
Currently unrated
What is CVE-2010-4408?
Apache Archiva versions 1.0 through 1.3.1 allow unauthorized modification of user accounts without requiring the administrator's password. This vulnerability poses a risk, especially in environments where workstations may be left unattended. Additionally, it can be exploited through a cross-site request forgery (CSRF) attack, enabling attackers to potentially elevate privileges. Organizations utilizing affected versions of Archiva are advised to implement security measures and apply patches to safeguard their systems.