CVE-2017-5657
Last modified
CVE-2017-5657 is a vulnerability of currently unknown severity. Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Archiva | <= 2.2.1 |
References
- http://archiva.apache.org/security.html#CVE-2017-5657Patch, Vendor Advisory
- http://www.securityfocus.com/bid/98570Third Party Advisory, VDB Entry
- http://archiva.apache.org/security.html#CVE-2017-5657Patch, Vendor Advisory
- http://www.securityfocus.com/bid/98570Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5657?
How severe is CVE-2017-5657?
How do I fix CVE-2017-5657?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-5651In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, …
- CVE-2017-5652During a routine security analysis, it was found that one of…
- CVE-2017-5653JAX-RS XML Security streaming clients in Apache CXF before 3…
- CVE-2017-5654In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authoriz…
- CVE-2017-5655In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive da…
- CVE-2017-5656Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawe…
- CVE-2017-5658The statistics generator in Apache Pony Mail 0.7 to 0.9 was …
- CVE-2017-5659Apache Traffic Server before 6.2.1 generates a coredump when…
- CVE-2017-5660There is a vulnerability in Apache Traffic Server (ATS) 6.2.…
- CVE-2017-5661In Apache FOP before 2.2, files lying on the filesystem of t…
- CVE-2017-5662In Apache Batik before 1.9, files lying on the filesystem of…
- CVE-2017-5663In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0…
Are you affected by CVE-2017-5657?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
