5
CVSSv2

CVE-2015-3184

Published: 12/08/2015 Updated: 01/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

mod_authz_svn in Apache Subversion 1.7.x prior to 1.7.21 and 1.8.x prior to 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

apple xcode

apache subversion 1.7.7

apache subversion 1.7.6

apache subversion 1.7.17

apache subversion 1.7.16

apache subversion 1.7.0

apache subversion 1.7.20

apache subversion 1.8.3

apache subversion 1.8.2

apache subversion 1.7.9

apache subversion 1.7.8

apache subversion 1.7.19

apache subversion 1.7.18

apache subversion 1.7.11

apache subversion 1.7.10

apache subversion 1.7.1

apache subversion 1.8.5

apache subversion 1.8.4

apache subversion 1.8.1

apache subversion 1.7.5

apache subversion 1.7.4

apache subversion 1.7.15

apache subversion 1.7.14

apache subversion 1.8.9

apache subversion 1.8.8

apache subversion 1.8.0

apache subversion 1.8.11

apache subversion 1.7.3

apache subversion 1.7.2

apache subversion 1.7.13

apache subversion 1.7.12

apache subversion 1.8.7

apache subversion 1.8.6

apache subversion 1.8.13

apache subversion 1.8.10

Vendor Advisories

Several security issues have been found in the server components of the version control system subversion CVE-2015-3184 Subversion's mod_authz_svn does not properly restrict anonymous access in some mixed anonymous/authenticated environments when using Apache httpd 24 The result is that anonymous access may be possible to files ...
It was found that the mod_authz_svn module did not properly restrict anonymous access to Subversion repositories under certain configurations when used with Apache httpd 24x This could allow a user to anonymously access files in a Subversion repository, which should only be accessible to authenticated users ...
For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available To learn more about Apple Product Security, see the Apple Product Security website For information about the Apple Product Security PGP Key, see How to use ...
Several security issues were fixed in Subversion ...
It was found that when an SVN server (both svnserve and httpd with the mod_dav_svn module) searched the history of a file or a directory, it would disclose its location in the repository if that file or directory was not readable (for example, if it had been moved) (CVE-2015-3187 ) An integer overflow was discovered allowing remote attackers to ex ...