GHSA-5p54-jj38-3hxj

Suggest an improvement
Source
https://github.com/advisories/GHSA-5p54-jj38-3hxj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5p54-jj38-3hxj/GHSA-5p54-jj38-3hxj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5p54-jj38-3hxj
Aliases
  • CVE-2010-4408
Published
2022-05-14T02:42:19Z
Modified
2025-04-12T02:42:07Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Apache Archiva does not require entry of the administrator's password at the time of modifying a user account
Details

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.

Database specific
{
    "cwe_ids":  [
        "CWE-862"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-04-12T01:42:05Z",
    "nvd_published_at":  "2010-12-06T20:13:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.apache.archiva:archiva

Package

Name
org.apache.archiva:archiva
View open source insights on deps.dev
Purl
pkg:maven/org.apache.archiva/archiva

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0
Fixed
1.3.2

Affected versions

1.*
1.1
1.1.1
1.1.2
1.1.3
1.1.4
1.2-M1
1.2
1.2.1
1.2.2
1.3
1.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5p54-jj38-3hxj/GHSA-5p54-jj38-3hxj.json"