Updated viewvc packages fix security vulnerability
Publication date: 24 Jan 2023Modification date: 24 Jan 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2023-22456 , CVE-2023-22464
Description
ViewVC is vulnerable to cross-site scripting. The impact of these vulnerabilities is mitigated by the need for an attacker to have commit privileges to a Subversion repository exposed by an otherwise trusted ViewVC instance. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. (CVE-2023-22456, CVE-2023-22464)
References
SRPMS
8/core
- viewvc-1.3.0-0.dev20200516.1.1.mga8