CVE-2008-1291: Infoleak
ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1291?
CVE-2008-1291 is considered a medium severity vulnerability as it exposes sensitive information due to insufficient access controls.
How does CVE-2008-1291 affect ViewVC users?
CVE-2008-1291 allows remote attackers to read files and list folders in the hidden CVSROOT folder, compromising sensitive data.
Which versions of ViewVC are affected by CVE-2008-1291?
CVE-2008-1291 affects ViewVC versions prior to 1.0.5, specifically 1.0.2 and 1.0.3.
How do I fix CVE-2008-1291?
To fix CVE-2008-1291, users should upgrade their ViewVC installation to version 1.0.5 or later to ensure proper access controls.
What are the potential consequences of CVE-2008-1291?
The potential consequences of CVE-2008-1291 include unauthorized access to version control files and possible data leakage.