PT-2020-18373 · Viewvc+1 · Viewvc+1

Cmpilatopublished

·

Published

2020-04-03

·

Updated

2024-06-15

·

CVE-2020-5283

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ViewVC versions prior to 1.1.28 ViewVC versions prior to 1.2.1
Description The issue is related to a XSS vulnerability in CVS show subdir lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the show subdir lastmod feature enabled. The attack vector involves files with unsafe names, which themselves can be challenging to create.
Recommendations For versions prior to 1.1.28, update to version 1.1.28 to resolve the issue. For versions prior to 1.2.1, update to version 1.2.1 to resolve the issue. As a temporary workaround, consider disabling the show subdir lastmod feature until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5283
GHSA-XPXF-FVQV-7MFG
MGASA-2020-0221
OPENSUSE-SU-2021:0084-1
OPENSUSE-SU-2021:0119-1
OPENSUSE-SU-2021:0123-1
OPENSUSE-SU-2021:0145-1
OPENSUSE-SU-2021_0084-1
OPENSUSE-SU-2021_0123-1
OPENSUSE-SU-2024:12857-1

Affected Products

Suse
Viewvc