XSS vulnerability in CVS show_subdir_lastmod support
Published Apr 3, 2020
3.5
LOWCVSS 3.1
EPSS 1.22%
Description
ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the `show_subdir_lastmod` feature enabled. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. This vulnerability is patched in versions 1.2.1 and 1.1.28.
Affected products
-
Affected
- < 1.1.28
- ≥ 1.2.0, < 1.2.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-26479 Advisory
- https://github.com/viewvc/viewvc/commit/ad0f966e9a997b17d853a6972ea283d4dcd70fa8 x_refsource_MISCPatchThird Party Advisory
- https://github.com/viewvc/viewvc/issues/211 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/viewvc/viewvc/security/advisories/GHSA-xpxf-fvqv-7mfg x_refsource_CONFIRMMitigationPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Q2STF2MKT24HXZ3YZIU7CN6F6QM67I5/ vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-26479 | Advisory | |
| https://github.com/viewvc/viewvc/commit/ad0f966e9a997b17d853a6972ea283d4dcd70fa8 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/viewvc/viewvc/issues/211 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://github.com/viewvc/viewvc/security/advisories/GHSA-xpxf-fvqv-7mfg | x_refsource_CONFIRMMitigationPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Q2STF2MKT24HXZ3YZIU7CN6F6QM67I5/ | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data