Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5p54-jj38-3hxj

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Apache Archiva does not require entry of the administrator's password at the time of modifying a user account

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.

Пакеты

Наименование

org.apache.archiva:archiva

maven
Затронутые версииВерсия исправления

>= 1.0, < 1.3.2

1.3.2

EPSS

Процентиль: 80%
0.01385
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-862

Связанные уязвимости

nvd
около 15 лет назад

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.

EPSS

Процентиль: 80%
0.01385
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-862