CVE-2010-0004

ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:viewvc:viewvc:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.1.2:*:*:*:*:*:*:*

History

07 Nov 2023, 02:04

Type Values Removed Values Added
References
  • {'url': 'http://viewvc.tigris.org/source/browse/*checkout*/viewvc/trunk/docs/release-notes/1.1.0.html?revision=2222', 'name': 'http://viewvc.tigris.org/source/browse/*checkout*/viewvc/trunk/docs/release-notes/1.1.0.html?revision=2222', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/trunk/docs/release-notes/1.1.0.html?revision=2222 -

Information

Published : 2010-01-29 18:30

Updated : 2023-12-10 11:03


NVD link : CVE-2010-0004

Mitre link : CVE-2010-0004

CVE.ORG link : CVE-2010-0004


JSON object : View

Products Affected

viewvc

  • viewvc
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor