ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC distribution can expose the contents of the host server's filesystem though a directory traversal-style attack. This is fixed in versions 1.1.31 and 1.2.4.
History

Wed, 23 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Viewvc
Viewvc viewvc
Vendors & Products Viewvc
Viewvc viewvc

Tue, 22 Jul 2025 21:45:00 +0000

Type Values Removed Values Added
Description ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC distribution can expose the contents of the host server's filesystem though a directory traversal-style attack. This is fixed in versions 1.1.31 and 1.2.4.
Title ViewVC's standalone server exposes arbitrary server filesystem content
Weaknesses CWE-22
CWE-79
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-22T21:35:47.844Z

Updated: 2025-07-23T18:31:31.496Z

Reserved: 2025-07-16T23:53:40.511Z

Link: CVE-2025-54141

cve-icon Vulnrichment

Updated: 2025-07-23T18:31:27.966Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-22T22:15:38.537

Modified: 2025-07-25T15:29:44.523

Link: CVE-2025-54141

cve-icon Redhat

No data.