Information disclosure in Subversion - CVE-2015-3184

 

Information disclosure in Subversion - CVE-2015-3184

Published: August 12, 2015 / Updated: July 28, 2020


Vulnerability identifier: #VU32390
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3184
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.


Affected software

Subversion
subversion (Alpine package)
subversion
Fedora

How to mitigate CVE-2015-3184

Install update from vendor's website.

Subversion - update to 1.7.21
subversion (Alpine package) - update to 1.8.14-r0
subversion - update to 1.8.14-1.fc22

External References

Related Security Bulletins