Information contained within a CVS directory left as a
subdirectory on a webserver (such as usernames, filenames, path root and IP
addresses) could be recovered by an attacker and used for malicious
purposes.
Time of Introduction
Operation
Potential Mitigations
Phase
Description
Recommendations include removing any CVS directories and repositories
from the production server, disabling the use of remote CVS
repositories, and ensuring that the latest CVS patches and version
updates have been performed.