Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-0749

Опубликовано: 23 дек. 2004
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:subversion:subversion:1.0:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.0_rc1:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.0_rc2:*:*:*:*:*:*:*
cpe:2.3:a:subversion:subversion:1.1.0_rc3:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:gentoo:linux:0.5:*:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:0.7:*:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.1a:*:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.2:*:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.4:*:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.4:rc1:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.4:rc2:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.4:rc3:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00619
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 20 лет назад

The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.

debian
больше 20 лет назад

The mod_authz_svn module in Subversion 1.0.7 and earlier does not prop ...

github
около 3 лет назад

The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.

EPSS

Процентиль: 69%
0.00619
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other