CVE-2010-3449

Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
jesse_mcconnellredback
𝑥
≤ 1.2.3
jesse_mcconnellredback
1.0
jesse_mcconnellredback
1.0:alpha4
jesse_mcconnellredback
1.0.1
jesse_mcconnellredback
1.0.2
jesse_mcconnellredback
1.0.3
jesse_mcconnellredback
1.1
jesse_mcconnellredback
1.1.1
jesse_mcconnellredback
1.1.2
jesse_mcconnellredback
1.2
jesse_mcconnellredback
1.2:beta1
jesse_mcconnellredback
1.2:beta2
jesse_mcconnellredback
1.2.1
jesse_mcconnellredback
1.2.2
apachearchiva
1.0
apachearchiva
1.0.1
apachearchiva
1.0.2
apachearchiva
1.0.3
apachearchiva
1.1
apachearchiva
1.1.1
apachearchiva
1.1.2
apachearchiva
1.1.3
apachearchiva
1.1.4
apachearchiva
1.2
apachearchiva
1.2.1
apachearchiva
1.2.2
apachearchiva
1.3
apachearchiva
1.3.1
𝑥
= Vulnerable software versions
References