CVE-2010-3449: CSRF
Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3449?
The severity of CVE-2010-3449 has been classified as a medium risk due to the potential for unauthorized access to administrative functions.
How do I fix CVE-2010-3449?
To fix CVE-2010-3449, upgrade Redback to version 1.2.4 or later, or apply any available patches provided by the vendor.
What systems are affected by CVE-2010-3449?
CVE-2010-3449 affects Redback versions prior to 1.2.4, as well as specific versions of Apache Archiva and Apache Continuum.
What type of vulnerability is CVE-2010-3449?
CVE-2010-3449 is a cross-site request forgery (CSRF) vulnerability that allows attackers to hijack the authentication of users.
Can CVE-2010-3449 be exploited remotely?
Yes, CVE-2010-3449 can be exploited remotely, allowing attackers to perform unauthorized actions as an authenticated user.