CVE-2017-5657 Vulnerability Details

  /     /     /  

CVE-2017-5657 Metadata Quick Info

CVE Published: 22/05/2017 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: apache | Vendor: Apache Software Foundation | Product: Apache Archiva
Status : PUBLISHED

CVE-2017-5657 Description

Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Apache Archiva CSRF vulnerabilities for various REST endpoints
Source: Apache Software Foundation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).