Multiple Vulnerabilities in Apache Archiva Through Version 1.3.4
Apache Archiva® is repository management software that developers use to archive multiple application revisions.
Affected Application: Apache Archiva 1.3.4. Previous versions are also affected.
Issue: On 06/02/11, multiple cross-site request forgery and cross-site scripting vulnerabilities were reported for Apache Archiva. The vulnerabilities let attackers gain unauthorized access, steal authentication credentials, and perform other malicious actions.
Resolution: An update for Apache Archiva is available. For more information, visit the vendor's website: http://archiva.apache.org/
This information was compiled using information in the National Vulnerability Database. For more information about this issue, see the following summaries:
CVE-2011-1026
CVE-2011-1077
To learn more about cross-site request forgery and cross-site scripting vulnerabilities, see Cross-Site Request Forgery and Cross-Site Scripting.
Website Protection Site Scanner scans for this vulnerability, and many more. To learn about Site Scanner, see Getting Started with Website Protection Site Scanner.