CVE Vulnerabilities

CVE-2010-0005

Published: Jan 29, 2010 | Modified: Feb 02, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.

Affected Software

Name Vendor Start Version End Version
Viewvc Viewvc * 1.1.2 (including)
Viewvc Viewvc 1.0.1 (including) 1.0.1 (including)
Viewvc Viewvc 1.0.2 (including) 1.0.2 (including)
Viewvc Viewvc 1.0.3 (including) 1.0.3 (including)
Viewvc Viewvc 1.0.4 (including) 1.0.4 (including)
Viewvc Viewvc 1.0.5 (including) 1.0.5 (including)
Viewvc Viewvc 1.0.6 (including) 1.0.6 (including)
Viewvc Viewvc 1.0.7 (including) 1.0.7 (including)
Viewvc Viewvc 1.0.8 (including) 1.0.8 (including)
Viewvc Viewvc 1.1.0 (including) 1.1.0 (including)
Viewvc Viewvc 1.1.1 (including) 1.1.1 (including)

References