4
CVSSv2

CVE-2015-3187

Published: 12/08/2015 Updated: 01/07/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The svn_repos_trace_node_locations function in Apache Subversion prior to 1.7.21 and 1.8.x prior to 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.

Vulnerable Product Search on Vulmon Subscribe to Product

apache subversion 1.8.1

apache subversion 1.8.2

apache subversion 1.8.3

apache subversion 1.8.10

apache subversion 1.8.11

apache subversion

apache subversion 1.8.8

apache subversion 1.8.9

apache subversion 1.8.6

apache subversion 1.8.7

apache subversion 1.8.4

apache subversion 1.8.5

apache subversion 1.8.13

apple xcode

Vendor Advisories

Several security issues were fixed in Subversion ...
Several security issues have been found in the server components of the version control system subversion CVE-2015-3184 Subversion's mod_authz_svn does not properly restrict anonymous access in some mixed anonymous/authenticated environments when using Apache httpd 24 The result is that anonymous access may be possible to files ...
It was found that when an SVN server (both svnserve and httpd with the mod_dav_svn module) searched the history of a file or a directory, it would disclose its location in the repository if that file or directory was not readable (for example, if it had been moved) (CVE-2015-3187) An integer overflow was discovered allowing remote attackers to exe ...
It was found that when an SVN server (both svnserve and httpd with the mod_dav_svn module) searched the history of a file or a directory, it would disclose its location in the repository if that file or directory was not readable (for example, if it had been moved) ...