Description
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).
Remediation
References
http://archiva.apache.org/security.html#CVE-2017-5657
http://www.securityfocus.com/bid/98570
http://www.securitytracker.com/id/1038528
https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
Related Vulnerabilities
CVE-2013-6430 Vulnerability in maven package org.springframework:spring-web
CVE-2016-10577 Vulnerability in npm package ibm_db
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_3
CVE-2020-11994 Vulnerability in maven package org.apache.camel:camel-robotframework
CVE-2023-43666 Vulnerability in maven package org.apache.inlong:manager-web