PT-2020-18373 · Viewvc+1 · Viewvc+1
Cmpilatopublished
·
Published
2020-04-03
·
Updated
2024-06-15
·
CVE-2020-5283
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ViewVC versions prior to 1.1.28
ViewVC versions prior to 1.2.1
Description
The issue is related to a XSS vulnerability in CVS show subdir lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the
show subdir lastmod feature enabled. The attack vector involves files with unsafe names, which themselves can be challenging to create.Recommendations
For versions prior to 1.1.28, update to version 1.1.28 to resolve the issue.
For versions prior to 1.2.1, update to version 1.2.1 to resolve the issue.
As a temporary workaround, consider disabling the
show subdir lastmod feature until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Viewvc