First published: Mon Dec 06 2010(Updated: )
Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jesse Mcconnell Redback | <=1.2.3 | |
Jesse Mcconnell Redback | =1.0 | |
Jesse Mcconnell Redback | =1.0-alpha4 | |
Jesse Mcconnell Redback | =1.0.1 | |
Jesse Mcconnell Redback | =1.0.2 | |
Jesse Mcconnell Redback | =1.0.3 | |
Jesse Mcconnell Redback | =1.1 | |
Jesse Mcconnell Redback | =1.1.1 | |
Jesse Mcconnell Redback | =1.1.2 | |
Jesse Mcconnell Redback | =1.2 | |
Jesse Mcconnell Redback | =1.2-beta1 | |
Jesse Mcconnell Redback | =1.2-beta2 | |
Jesse Mcconnell Redback | =1.2.1 | |
Jesse Mcconnell Redback | =1.2.2 | |
Apache Archiva | =1.0 | |
Apache Archiva | =1.0.1 | |
Apache Archiva | =1.0.2 | |
Apache Archiva | =1.0.3 | |
Apache Archiva | =1.1 | |
Apache Archiva | =1.1.1 | |
Apache Archiva | =1.1.2 | |
Apache Archiva | =1.1.3 | |
Apache Archiva | =1.1.4 | |
Apache Archiva | =1.2 | |
Apache Archiva | =1.2.1 | |
Apache Archiva | =1.2.2 | |
Apache Archiva | =1.3 | |
Apache Archiva | =1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.