CVE-2010-3449

Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:jesse_mcconnell:redback:*:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.0:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.1:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.2:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.2:beta1:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.2:beta2:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:jesse_mcconnell:redback:1.2.2:*:*:*:*:*:*:*
OR cpe:2.3:a:apache:archiva:1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:archiva:1.3.1:*:*:*:*:*:*:*

History

07 Nov 2023, 02:05

Type Values Removed Values Added
References
  • {'url': 'http://mail-archives.apache.org/mod_mbox/continuum-users/201102.mbox/%3C032C189E-D821-4833-A8F2-F72365147695@apache.org%3E', 'name': '[continuum-users] 20110210 [SECURITY] CVE-2010-3449: Apache Continuum CSRF vulnerability', 'tags': [], 'refsource': 'MLIST'}
  • {'url': 'http://mail-archives.apache.org/mod_mbox/archiva-users/201011.mbox/ajax/%3CAANLkTimXejHAuXdoUKLN=GkNty1_XnRCbv0YA0T2cS_2@mail.gmail.com%3E', 'name': '[archiva-users] 20101129 Apache Archiva CSRF Vulnerability', 'tags': [], 'refsource': 'MLIST'}
  • () http://mail-archives.apache.org/mod_mbox/archiva-users/201011.mbox/ajax/%3CAANLkTimXejHAuXdoUKLN=GkNty1_XnRCbv0YA0T2cS_2%40mail.gmail.com%3E -
  • () http://mail-archives.apache.org/mod_mbox/continuum-users/201102.mbox/%3C032C189E-D821-4833-A8F2-F72365147695%40apache.org%3E -

Information

Published : 2010-12-06 20:13

Updated : 2023-12-10 11:03


NVD link : CVE-2010-3449

Mitre link : CVE-2010-3449

CVE.ORG link : CVE-2010-3449


JSON object : View

Products Affected

apache

  • archiva

jesse_mcconnell

  • redback
CWE
CWE-352

Cross-Site Request Forgery (CSRF)