CVE-2020-5283

Public Exploit
XSS vulnerability in CVS show_subdir_lastmod support

Description

ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the `show_subdir_lastmod` feature enabled. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. This vulnerability is patched in versions 1.2.1 and 1.1.28.

Categories

3.1
CVSS
Severity: Low
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.41%
Vendor Advisory fedoraproject.org
Affected: viewvc viewvc
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2020-5283?
CVE-2020-5283 has been scored as a low severity vulnerability.
How to fix CVE-2020-5283?
To fix CVE-2020-5283, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2020-5283 being actively exploited in the wild?
It is possible that CVE-2020-5283 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2020-5283?
CVE-2020-5283 affects viewvc viewvc.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.