Back

LOW

subversion: revision properties disclosure to user with partial access

Published Jun 14, 2007

Description

Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.

Affected products

Remediation

Red Hat statement

The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw.

Metrics

Weaknesses (0)

No CWE recorded.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 14, 2007
Updated Aug 7, 2024
Reserved May 2, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 6, 2007