Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-3187


The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.


Published

2015-08-12T14:59:12.150

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache subversion ≤ 1.7.20 Yes
Application apache subversion 1.8.1 Yes
Application apache subversion 1.8.2 Yes
Application apache subversion 1.8.3 Yes
Application apache subversion 1.8.4 Yes
Application apache subversion 1.8.5 Yes
Application apache subversion 1.8.6 Yes
Application apache subversion 1.8.7 Yes
Application apache subversion 1.8.8 Yes
Application apache subversion 1.8.9 Yes
Application apache subversion 1.8.10 Yes
Application apache subversion 1.8.11 Yes
Application apache subversion 1.8.13 Yes
Application apple xcode ≤ 7.2.1 Yes

References