Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2023.0019
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2023-0019)
Zusammenfassung:The remote host is missing an update for the 'viewvc' package(s) announced via the MGASA-2023-0019 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'viewvc' package(s) announced via the MGASA-2023-0019 advisory.

Vulnerability Insight:
ViewVC is vulnerable to cross-site scripting. The impact of these
vulnerabilities is mitigated by the need for an attacker to have commit
privileges to a Subversion repository exposed by an otherwise trusted
ViewVC instance. The attack vector involves files with unsafe names (names
that, when embedded into an HTML stream, would cause the browser to run
unwanted code), which themselves can be challenging to create.
(CVE-2023-22456, CVE-2023-22464)

Affected Software/OS:
'viewvc' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2023-22456
https://github.com/viewvc/viewvc/issues/311
https://github.com/viewvc/viewvc/releases/tag/1.1.29
https://github.com/viewvc/viewvc/releases/tag/1.2.2
https://github.com/viewvc/viewvc/security/advisories/GHSA-j4mx-f97j-gc5g
Common Vulnerability Exposure (CVE) ID: CVE-2023-22464
https://github.com/viewvc/viewvc/releases/tag/1.1.30
https://github.com/viewvc/viewvc/releases/tag/1.2.3
https://github.com/viewvc/viewvc/security/advisories/GHSA-jvpj-293q-q53h
CopyrightCopyright (C) 2023 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.