ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-apps/viewvc. | Oct 30, 2017 | Mar 24, 2008 |
| Suse | — | Upgrade cvs2svnUpgrade subversion-pythonUpgrade subversion-toolsUpgrade subversion-serverUpgrade subversion-develUpgrade subversionUpgrade viewcvsUpgrade viewvcUpgrade suse-release | Feb 17, 2015 | Mar 24, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub