cbcvebase.
CVE-2010-3449
published 2010-12-06

CVE-2010-3449: Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and…

PriorityP338medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
4.84%
90.9th percentile
Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.

Affected

25 ranges
VendorProductVersion rangeFixed in
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
apachearchiva
jesse_mcconnellredback<= 1.2.3
jesse_mcconnellredback
jesse_mcconnellredback
jesse_mcconnellredback
jesse_mcconnellredback
jesse_mcconnellredback
jesse_mcconnellredback
jesse_mcconnellredback
jesse_mcconnellredback
jesse_mcconnellredback
jesse_mcconnellredback

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa6.8MEDIUM
osv6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.