5
CVSSv2

CVE-2015-3184

Published: 12/08/2015 Updated: 01/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

mod_authz_svn in Apache Subversion 1.7.x prior to 1.7.21 and 1.8.x prior to 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple xcode

apache subversion 1.7.7

apache subversion 1.7.6

apache subversion 1.7.17

apache subversion 1.7.16

apache subversion 1.7.0

apache subversion 1.7.20

apache subversion 1.8.3

apache subversion 1.8.2

apache subversion 1.7.9

apache subversion 1.7.8

apache subversion 1.7.19

apache subversion 1.7.18

apache subversion 1.7.11

apache subversion 1.7.10

apache subversion 1.7.1

apache subversion 1.8.5

apache subversion 1.8.4

apache subversion 1.8.1

apache subversion 1.7.5

apache subversion 1.7.4

apache subversion 1.7.15

apache subversion 1.7.14

apache subversion 1.8.9

apache subversion 1.8.8

apache subversion 1.8.0

apache subversion 1.8.11

apache subversion 1.7.3

apache subversion 1.7.2

apache subversion 1.7.13

apache subversion 1.7.12

apache subversion 1.8.7

apache subversion 1.8.6

apache subversion 1.8.13

apache subversion 1.8.10

Vendor Advisories

Several security issues were fixed in Subversion ...
Several security issues have been found in the server components of the version control system subversion CVE-2015-3184 Subversion's mod_authz_svn does not properly restrict anonymous access in some mixed anonymous/authenticated environments when using Apache httpd 24 The result is that anonymous access may be possible to files ...
It was found that when an SVN server (both svnserve and httpd with the mod_dav_svn module) searched the history of a file or a directory, it would disclose its location in the repository if that file or directory was not readable (for example, if it had been moved) (CVE-2015-3187) An integer overflow was discovered allowing remote attackers to exe ...
It was found that the mod_authz_svn module did not properly restrict anonymous access to Subversion repositories under certain configurations when used with Apache httpd 24x This could allow a user to anonymously access files in a Subversion repository, which should only be accessible to authenticated users ...