SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-4408

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain…

MEDIUM 6.8EPSS 2.02%

Does this matter?

Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.

Description

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.02% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
apache/archiva
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.