MGASA-2023-0019 - Updated viewvc packages fix security vulnerability Publication date: 24 Jan 2023 URL: https://advisories.mageia.org/MGASA-2023-0019.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-22456, CVE-2023-22464 ViewVC is vulnerable to cross-site scripting. The impact of these vulnerabilities is mitigated by the need for an attacker to have commit privileges to a Subversion repository exposed by an otherwise trusted ViewVC instance. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. (CVE-2023-22456, CVE-2023-22464) References: - https://bugs.mageia.org/show_bug.cgi?id=31417 - https://www.debian.org/lts/security/2023/dla-3266 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22456 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22464 SRPMS: - 8/core/viewvc-1.3.0-0.dev20200516.1.1.mga8