cbcvebase.
CVE-2017-5657
published 2017-05-22

CVE-2017-5657: Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same…

PriorityP433high8CVSS 3.0
AVNACLPRLUIRSUCHIHAH
EPSS
0.87%
54.7th percentile
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).

Affected

5 ranges
VendorProductVersion rangeFixed in
apachearchiva<= 2.2.1
apache_software_foundationapache_archiva
apache_software_foundationapache_archiva
apache_software_foundationapache_archiva
apache_software_foundationapache_archiva

CVSS provenance

nvdv3.08.0HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.