CVS Repository Detected

Medium Web Application Scanning Plugin ID 98680

Synopsis

CVS Repository Detected

Description

The web server on the remote host allows read access to files within a 'CVSROOT' directory exposing files tracked inside. This potential flaw can be used to access content from the web server that might otherwise be private & permit download of the source code of listed pages hosted on the remote server.

Solution

Restrict access to the CVSROOT directory or remove it.

Plugin Details

Severity: Medium

ID: 98680

Type: remote

Published: 2019/08/12

Updated: 2020/06/25

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3.0

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Reference Information

CWE: 538

WASC: Predictable Resource Location

OWASP: 2017-A6, 2013-A5, 2010-A6