CVE-2017-5657
published 2017-05-22CVE-2017-5657: Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same…
PriorityP433high8CVSS 3.0
AVNACLPRLUIRSUCHIHAH
EPSS
0.87%
54.7th percentile
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | archiva | <= 2.2.1 | — |
| apache_software_foundation | apache_archiva | — | — |
| apache_software_foundation | apache_archiva | — | — |
| apache_software_foundation | apache_archiva | — | — |
| apache_software_foundation | apache_archiva | — | — |
CVSS provenance
nvdv3.08.0HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Archiva vulnerable to Cross Site Request Forgery
osv·2022-05-14
CVE-2017-5657 [HIGH] Apache Archiva vulnerable to Cross Site Request Forgery
Apache Archiva vulnerable to Cross Site Request Forgery
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).
GHSA
Apache Archiva vulnerable to Cross Site Request Forgery
ghsa·2022-05-14
CVE-2017-5657 [HIGH] CWE-352 Apache Archiva vulnerable to Cross Site Request Forgery
Apache Archiva vulnerable to Cross Site Request Forgery
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archiva.apache.org/security.html#CVE-2017-5657http://www.securityfocus.com/bid/98570http://www.securitytracker.com/id/1038528https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttp://archiva.apache.org/security.html#CVE-2017-5657http://www.securityfocus.com/bid/98570http://www.securitytracker.com/id/1038528https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
2017-05-22
Published