AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2010-4408

MEDIUM · CVSS 6.8 EPSS 2.02%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-12-06 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.8. It affects Apache.

CVE
CVE-2010-4408
Severity
MEDIUM
CVSS
6.8
EPSS
2.02%
Apache

Original NVD Description

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.