Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3184

Опубликовано: 05 авг. 2015
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

It was found that the mod_authz_svn module did not properly restrict anonymous access to Subversion repositories under certain configurations when used with Apache httpd 2.4.x. This could allow a user to anonymously access files in a Subversion repository, which should only be accessible to authenticated users.

Отчет

This issue did not affect versions of subversion as shipped with Red Hat Enterprise Linux 5 and 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5subversionNot affected
Red Hat Enterprise Linux 6subversionNot affected
Red Hat Enterprise Linux 7subversionFixedRHSA-2015:174208.09.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1247249subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4

EPSS

Процентиль: 96%
0.22431
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

nvd
около 10 лет назад

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

debian
около 10 лет назад

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x befor ...

github
больше 3 лет назад

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

suse-cvrf
около 10 лет назад

Security update for subversion

EPSS

Процентиль: 96%
0.22431
Средний

4.3 Medium

CVSS2