Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1921

Опубликовано: 06 июн. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.

РелизСтатусПримечание
devel

released

1.6.12dfsg-4ubuntu5
hardy

ignored

end of life
lucid

released

1.6.6dfsg-2ubuntu1.3
maverick

released

1.6.12dfsg-1ubuntu1.3
natty

released

1.6.12dfsg-4ubuntu2.1
upstream

released

1.6.17

Показывать по

EPSS

Процентиль: 87%
0.03643
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.

nvd
около 14 лет назад

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.

debian
около 14 лет назад

The mod_dav_svn module for the Apache HTTP Server, as distributed in A ...

github
около 3 лет назад

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.

oracle-oval
около 14 лет назад

ELSA-2011-0862: subversion security update (MODERATE)

EPSS

Процентиль: 87%
0.03643
Низкий

4.3 Medium

CVSS2