7.5
CVSSv3

CVE-2022-24070

Published: 12/04/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 up to and including 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache subversion

debian debian linux 10.0

debian debian linux 11.0

fedoraproject fedora 35

fedoraproject fedora 36

apple macos

Vendor Advisories

Several security issues were fixed in Subversion ...
Several security issues were fixed in subversion ...
Several vulnerabilities were discovered in Subversion, a version control system CVE-2021-28544 Evgeny Kotkov reported that Subversion servers reveal copyfrom paths that should be hidden according to configured path-based authorization (authz) rules CVE-2022-24070 Thomas Weissschuh reported that Subversion's mod_dav_svn is prone t ...
Synopsis Important: subversion:114 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the subversion:114 module is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Ha ...
Synopsis Important: subversion:110 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the subversion:110 module is now available for Red Hat Enterprise Linux 82 Extended Update SupportRed Ha ...
Synopsis Important: subversion:110 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the subversion:110 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rat ...
Synopsis Important: subversion:114 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the subversion:114 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rat ...
Synopsis Important: subversion security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subversion is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as hav ...
概述 Important: subversion:110 security update 类型/严重性 Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems 标题 An update for the subversion:110 module is now available for Red Hat Enterprise Linux 81 Update Services for SAP Solu ...
Synopsis Important: subversion:110 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the subversion:110 module is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Ha ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2750 subversion 1141-6 1142-1 Unknown Vulnerable ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...
A use-after-free vulnerability was found in Subversion in the mod_dav_svn Apache HTTP server (HTTPd) module While looking up path-based authorization (authz) rules, multiple calls to the post_config hook can invalidate cached pointers to object-pools, which Subversion subsequently uses This issue crashes the single HTTPd worker thread or the enti ...
A flaw was found in Subversion When using path-based authorization (authz), the helper function detect_changed() does not omit potentially sensitive information from log messages In particular, if a node is copied from a protected location, its copyfrom path (the path to the protected location) is reported even when omission should occur (CVE-20 ...