Path-Based Authorization Flaw in Apache Subversion
CVE-2015-3187

Currently unrated

Key Information:

Vendor
Apache
Vendor
CVE Published:
12 August 2015

Summary

The svn_repos_trace_node_locations function in Apache Subversion contains a flaw that allows remote authenticated users to gain access to sensitive path information. This occurs when path-based authorization is enabled and users are able to read the history of a node that has been moved from a hidden path. Such exposure could potentially lead to the unauthorized retrieval of critical operational data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.