4.3
CVSSv3

CVE-2021-28544

Published: 12/04/2022 Updated: 11/02/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache subversion

debian debian linux 10.0

debian debian linux 11.0

fedoraproject fedora 35

fedoraproject fedora 36

apple macos

Vendor Advisories

Several security issues were fixed in Subversion ...
Several security issues were fixed in subversion ...
Several vulnerabilities were discovered in Subversion, a version control system CVE-2021-28544 Evgeny Kotkov reported that Subversion servers reveal copyfrom paths that should be hidden according to configured path-based authorization (authz) rules CVE-2022-24070 Thomas Weissschuh reported that Subversion's mod_dav_svn is prone t ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2750 subversion 1141-6 1142-1 Unknown Vulnerable ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...
A flaw was found in Subversion When using path-based authorization (authz), the helper function detect_changed() does not omit potentially sensitive information from log messages In particular, if a node is copied from a protected location, its copyfrom path (the path to the protected location) is reported even when omission should occur (CVE-20 ...