jira.codehaus.org

  • Log In Access more options
    • Online Help
    • Keyboard Shortcuts
    • About JIRA
    • JIRA Credits
    • What?s New
  • Dashboards Access more options (Alt+d)
  • Projects Access more options (Alt+p)
  • Issues Access more options (Alt+i)
  • Archiva
  • MRM-1438

CSRF vulnerability - Archiva doesn't check which form sends credentials

  • Log In
  • Views
    • XML
    • Word
    • Printable

Details

  • Type: Bug Bug
  • Status: Closed Closed
  • Priority: Critical Critical
  • Resolution: Fixed
  • Affects Version/s: 1.3.1
  • Fix Version/s: 1.3.2
  • Component/s: Users/Security
  • Labels:
    None

Description

As reported by Anatolia Security Research Group, Apache Archiva doesn't check which form sends credentials. An attacker can create a specially crafted page and force archiva administrators to view it and change their credentials.

Vulnerability reference key: [CVE-2010-3449] Apache Archiva CSRF Vulnerability

Activity

  • All
  • Comments
  • Work Log
  • History
  • Activity
Hide
Permalink
Maria Odea Ching added a comment - 29/Nov/10 8:46 PM

Fixed in -r1038518:

  • upgrade to Redback 1.2.4 where this issue was fixed
  • enable referrer check by default for security interceptor in Archiva
Show
Maria Odea Ching added a comment - 29/Nov/10 8:46 PM Fixed in -r1038518:
  • upgrade to Redback 1.2.4 where this issue was fixed
  • enable referrer check by default for security interceptor in Archiva

People

  • Assignee:
    Maria Odea Ching
    Reporter:
    Maria Odea Ching
Vote (0)
Watch (0)

Dates

  • Created:
    29/Nov/10 8:41 PM
    Updated:
    29/Nov/10 8:46 PM
    Resolved:
    29/Nov/10 8:46 PM
  • Atlassian JIRA (v5.0.4#731-sha1:3aa7374)
  • Report a problem
  • Powered by a free Atlassian JIRA open source license for Codehaus. Try JIRA - bug tracking software for your team.