Advisories ยป MGASA-2023-0019

Updated viewvc packages fix security vulnerability

Publication date: 24 Jan 2023
Modification date: 24 Jan 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2023-22456 , CVE-2023-22464

Description

ViewVC is vulnerable to cross-site scripting. The impact of these
vulnerabilities is mitigated by the need for an attacker to have commit
privileges to a Subversion repository exposed by an otherwise trusted
ViewVC instance. The attack vector involves files with unsafe names (names
that, when embedded into an HTML stream, would cause the browser to run
unwanted code), which themselves can be challenging to create.
(CVE-2023-22456, CVE-2023-22464)
                

References

SRPMS

8/core