Back

MEDIUM

Apache Subversion SVN authz protected copyfrom paths regression

Published Apr 12, 2022

Description

Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.

Affected products

Remediation

No remediation recorded yet.

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Apr 12, 2022
Updated Aug 3, 2024
Reserved Mar 16, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Mar 27, 2022
Bugzilla 2074780

ENISA EUVD

Assigner apache
Published Apr 12, 2022
Updated Aug 3, 2024

GitHub

No data