Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jesse Mcconnell | Redback | <= 1.2.3 |
| Apache | Archiva | 1.0 |
Related Weaknesses (CWE)
References
- http://archiva.apache.org/security.html
- http://continuum.apache.org/security.html
- http://jira.codehaus.org/browse/MRM-1438
- http://mail-archives.apache.org/mod_mbox/archiva-users/201011.mbox/ajax/%3CAANLk
- http://mail-archives.apache.org/mod_mbox/continuum-users/201102.mbox/%3C032C189E
- http://seclists.org/fulldisclosure/2011/Feb/238
- http://secunia.com/advisories/42376Vendor Advisory
- http://secunia.com/advisories/43261
- http://svn.apache.org/viewvc/archiva/branches/archiva-1.3.x/archiva-modules/archPatch
- http://svn.apache.org/viewvc/archiva/branches/archiva-1.3.x/pom.xml?r1=1038518&rPatch
- http://svn.apache.org/viewvc?view=revision&revision=1038518
- http://svn.apache.org/viewvc?view=revision&revision=1066010
- http://www.osvdb.org/69520
- http://www.securityfocus.com/archive/1/514937/100/0/threaded
- http://www.securityfocus.com/archive/1/516341/100/0/threaded
FAQ
What is CVE-2010-3449?
CVE-2010-3449 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum ...
How severe is CVE-2010-3449?
CVE-2010-3449 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3449?
Check the references section above for vendor advisories and patch information. Affected products include: Jesse Mcconnell Redback, Apache Archiva.