Log Message Leakage in ViewVC SVN Revision View

Log Message Leakage in ViewVC SVN Revision View

CVE-2012-3357 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a "log msg leak."

Learn more about our Web Application Penetration Testing UK.