Cross Site Request Forgery Vulnerability in Apache Archiva
CVE-2017-5657
8HIGH
What is CVE-2017-5657?
Apache Archiva has a vulnerability in several of its REST service endpoints that are inadequate against Cross Site Request Forgery (CSRF) attacks. This flaw allows a malicious actor to exploit the vulnerability by tricking an authenticated user into visiting a malicious site. Once the user’s Archiva session is active, the attacker can send crafted requests that execute arbitrary actions on the Archiva services with the user’s privileges, including those of an administrator. Consequently, this vulnerability poses serious risks as it could lead to unauthorized access and manipulation of Archiva resources.
Affected Version(s)
Apache Archiva 1.x
Apache Archiva 2.0.0, 2.0.1
Apache Archiva 2.1.0, 2.1.1