Information disclosure in Subversion - CVE-2015-3184

 

Information disclosure in Subversion - CVE-2015-3184

Published: August 12, 2015 / Updated: July 28, 2020


Vulnerability identifier: #VU32390
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2015-3184
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Apache Foundation
Affected software:
Subversion

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.


How to mitigate CVE-2015-3184

Install update from vendor's website.

Sources