关键漏洞信息 漏洞标题 Standalone server exposes arbitrary server filesystem content 严重性 Severity: High (7.5/10) 影响版本 Affected versions: >=1.1.0, =1.2.0, <=1.2.3 修复版本 Patched versions: 1.1.31; 1.2.4 描述 The ViewVC standalone web server ( ) can expose the contents of the host server's filesystem through a directory traversal-style attack. 影响 Users can craft HTTP requests to access host filesystem directories outside the targeted CVS repository if the server is remotely accessible and CVS repositories are configured for public browsing. 修复措施 Upgrade to ViewVC version 1.2.4. If bound to the 1.1.x release line, upgrade to 1.1.31. 绕过方法 Manually apply patches from: 1.1.x: commit link 1.2.x: commit link 弱点 CWE-22 CWE-497 CVE ID CVE-2025-54141