Lucene search

K
cveRedhatCVE-2010-0005
HistoryJan 29, 2010 - 6:30 p.m.

CVE-2010-0005

2010-01-2918:30:01
CWE-264
redhat
web.nvd.nist.gov
34
cve
viewvc
query.py
access restrictions
bypass
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.013

Percentile

86.4%

query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.

Affected configurations

Nvd
Node
viewvcviewvcRange1.1.2
OR
viewvcviewvcMatch1.0.1
OR
viewvcviewvcMatch1.0.2
OR
viewvcviewvcMatch1.0.3
OR
viewvcviewvcMatch1.0.4
OR
viewvcviewvcMatch1.0.5
OR
viewvcviewvcMatch1.0.6
OR
viewvcviewvcMatch1.0.7
OR
viewvcviewvcMatch1.0.8
OR
viewvcviewvcMatch1.1.0
OR
viewvcviewvcMatch1.1.1
VendorProductVersionCPE
viewvcviewvc*cpe:2.3:a:viewvc:viewvc:*:*:*:*:*:*:*:*
viewvcviewvc1.0.1cpe:2.3:a:viewvc:viewvc:1.0.1:*:*:*:*:*:*:*
viewvcviewvc1.0.2cpe:2.3:a:viewvc:viewvc:1.0.2:*:*:*:*:*:*:*
viewvcviewvc1.0.3cpe:2.3:a:viewvc:viewvc:1.0.3:*:*:*:*:*:*:*
viewvcviewvc1.0.4cpe:2.3:a:viewvc:viewvc:1.0.4:*:*:*:*:*:*:*
viewvcviewvc1.0.5cpe:2.3:a:viewvc:viewvc:1.0.5:*:*:*:*:*:*:*
viewvcviewvc1.0.6cpe:2.3:a:viewvc:viewvc:1.0.6:*:*:*:*:*:*:*
viewvcviewvc1.0.7cpe:2.3:a:viewvc:viewvc:1.0.7:*:*:*:*:*:*:*
viewvcviewvc1.0.8cpe:2.3:a:viewvc:viewvc:1.0.8:*:*:*:*:*:*:*
viewvcviewvc1.1.0cpe:2.3:a:viewvc:viewvc:1.1.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.013

Percentile

86.4%