Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
subversion vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2021-44478
A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scripting is present due to improper neutralization of data sent to the web page through the SVN WebClient in the affected product. An attack...
Siemens Polarion Subversion Webclient
Siemens Polarion Alm
Siemens Polarion Alm 21.0
5
CVSSv2
CVE-2021-21698
Jenkins Subversion Plugin 2.15.0 and previous versions does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
Jenkins Subversion
4.3
CVSSv2
CVE-2020-17525
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was ...
Apache Subversion
Debian Debian Linux 9.0
4
CVSSv2
CVE-2020-2304
Jenkins Subversion Plugin 2.13.1 and previous versions does not configure its XML parser to prevent XML external entity (XXE) attacks.
Jenkins Subversion
4.3
CVSSv2
CVE-2020-15788
A vulnerability has been identified in Polarion Subversion Webclient (All versions). The Polarion subversion web application does not filter user input in a way that prevents Cross-Site Scripting. If a user is enticed into passing specially crafted, malicious input to the web cli...
Siemens Polarion Subversion Webclient
5.8
CVSSv2
CVE-2020-15789
A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a...
Siemens Polarion Subversion Webclient
4.3
CVSSv2
CVE-2020-2199
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and previous versions does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.
Jenkins Subversion Partial Release Manager
4.3
CVSSv2
CVE-2020-9344
Subversion ALM for the enterprise prior to 8.8.2 allows reflected XSS at multiple locations.
Atlassian Subversion Application Lifecycle Management
4.3
CVSSv2
CVE-2020-2152
Jenkins Subversion Release Manager Plugin 1.2 and previous versions does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.
Jenkins Subversion Release Manager
3.5
CVSSv2
CVE-2020-2111
Jenkins Subversion Plugin 2.13.0 and previous versions does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.
Jenkins Subversion
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »