{"id":"MGASA-2023-0019","summary":"Updated viewvc packages fix security vulnerability","details":"ViewVC is vulnerable to cross-site scripting. The impact of these\nvulnerabilities is mitigated by the need for an attacker to have commit\nprivileges to a Subversion repository exposed by an otherwise trusted\nViewVC instance. The attack vector involves files with unsafe names (names\nthat, when embedded into an HTML stream, would cause the browser to run\nunwanted code), which themselves can be challenging to create.\n(CVE-2023-22456, CVE-2023-22464)\n","modified":"2026-04-16T04:43:00.019494460Z","published":"2023-01-24T07:58:25Z","upstream":["CVE-2023-22456","CVE-2023-22464"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0019.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31417"},{"type":"WEB","url":"https://www.debian.org/lts/security/2023/dla-3266"}],"affected":[{"package":{"name":"viewvc","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/viewvc?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.0-0.dev20200516.1.1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0019.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}