Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8: 2023-0019 Critical: ViewVC Cross-Site Scripting

mageia
Calendar Grey January 24, 2023
Dist Mageia Esm H88
Recent ViewVC updates for Mageia address a significant cross-site scripting flaw that requires commit privileges for successful exploitation.
ViewVC is vulnerable to cross-site scripting

Summary

ViewVC is vulnerable to cross-site scripting. The impact of these vulnerabilities is mitigated by the need for an attacker to have commit privileges to a Subversion repository exposed by an otherwise trusted ViewVC instance. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. (CVE-2023-22456, CVE-2023-22464)

References

- https://bugs.mageia.org/show_bug.cgi?id=31417

- https://lists.debian.org/debian-lts-announce/2023/01/msg00006.html

- https://www.cve.org/CVERecord?id=CVE-2023-22456

- https://www.cve.org/CVERecord?id=CVE-2023-22464

Resolution

SRPMS

- 8/core/viewvc-1.3.0-0.dev20200516.1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 Jan 2023
URL: https://advisories.mageia.org/MGASA-2023-0019.html
Type: security
CVE: CVE-2023-22456, CVE-2023-22464

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here