ViewVC is vulnerable to cross-site scripting. The impact of these
vulnerabilities is mitigated by the need for an attacker to have commit
privileges to a Subversion repository exposed by an otherwise trusted
ViewVC instance. The attack vector involves files with unsafe names (names
that, when embedded into an HTML stream, would cause the browser to run
unwanted code), which themselves can be challenging to create.
(CVE-2023-22456, CVE-2023-22464)
- https://bugs.mageia.org/show_bug.cgi?id=31417
- https://lists.debian.org/debian-lts-announce/2023/01/msg00006.html
- https://www.cve.org/CVERecord?id=CVE-2023-22456
- https://www.cve.org/CVERecord?id=CVE-2023-22464
- 8/core/viewvc-1.3.0-0.dev20200516.1.1.mga8
Get the latest Linux and open source security news straight to your inbox.