CVE-2010-3449
Summary
| CVE | CVE-2010-3449 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-06 20:13:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Archiva | 1.0 | All | All | All |
| Application | Apache | Archiva | 1.0.1 | All | All | All |
| Application | Apache | Archiva | 1.0.2 | All | All | All |
| Application | Apache | Archiva | 1.0.3 | All | All | All |
| Application | Apache | Archiva | 1.1 | All | All | All |
| Application | Apache | Archiva | 1.1.1 | All | All | All |
| Application | Apache | Archiva | 1.1.2 | All | All | All |
| Application | Apache | Archiva | 1.1.3 | All | All | All |
| Application | Apache | Archiva | 1.1.4 | All | All | All |
| Application | Apache | Archiva | 1.2 | All | All | All |
| Application | Apache | Archiva | 1.2.1 | All | All | All |
| Application | Apache | Archiva | 1.2.2 | All | All | All |
| Application | Apache | Archiva | 1.3 | All | All | All |
| Application | Apache | Archiva | 1.3.1 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.0 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.0 | alpha4 | All | All |
| Application | Jesse Mcconnell | Redback | 1.0.1 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.0.2 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.0.3 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.1 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.1.1 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.1.2 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.2 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.2 | beta1 | All | All |
| Application | Jesse Mcconnell | Redback | 1.2 | beta2 | All | All |
| Application | Jesse Mcconnell | Redback | 1.2.1 | All | All | All |
| Application | Jesse Mcconnell | Redback | 1.2.2 | All | All | All |
| Application | Jesse Mcconnell | Redback | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache Continuum Cross-Site Scripting and Request Forgery Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.osvdb.org/69520 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Apache Continuum Input Validation Flaw Permits Cross-Site Request Forgery Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Full Disclosure: [SECURITY] CVE-2010-3449: Apache Continuum CSRF vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Archiva - Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | archiva.apache.org | |
| Continuum - Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | continuum.apache.org | |
| Apache Archiva Cross Site Request Forgery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apache Archiva Cross-Site Request Forgery Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [Apache-SVN] Revision 1038518 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [Apache-SVN] Diff of /archiva/branches/archiva-1.3.x/archiva-modules/archiva-web/archiva-webapp/src/main/resources/struts.xml | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Patch |
| mail-archives.apache.org/mod_mbox/archiva-users/201011.mbox/ajax/%3CAANLkTimXejHAuXdoU... | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | |
| [Apache-SVN] Revision 1066010 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| [Apache-SVN] Diff of /archiva/branches/archiva-1.3.x/pom.xml | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Patch |
| [#MRM-1438] CSRF vulnerability - Archiva doesn't check which form sends credentials - jira.codehaus.org | af854a3a-2127-422b-91ae-364da2661108 | jira.codehaus.org | |
| [SECURITY] CVE-2010-3449: Apache Continuum CSRF vulnerability | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | |
| MLIST:[archiva-users] 20101129 Apache Archiva CSRF Vulnerability | MITRE | mail-archives.apache.org | |
| [SECURITY] CVE-2010-3449: Apache Continuum CSRF vulnerability | MITRE | mail-archives.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.