漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Archiva 跨站请求伪造漏洞
Vulnerability Description
Apache Archiva是美国阿帕奇(Apache)软件基金会的一套用于管理一个或多个远程存储的软件。该软件提供远程Repository代理、基于角色的安全访问管理和使用情况报告等功能。 Apache Archiva中的REST service endpoints存在跨站请求伪造漏洞。远程攻击者可利用该漏洞执行未授权的操作。
CVSS Information
N/A
Vulnerability Type
N/A