Apache Subversion SVN authz protected copyfrom paths regression
Published Apr 12, 2022
4.3
MEDIUMCVSS 3.1
EPSS 2.79%
Description
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
Affected products
-
Affected
- 1.10.0 to 1.14.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Subversion | unknown | Affected
|
Configuration 1
- ≥ 1.10.0 · ≤ 1.14.1
Configuration 2
- 10.0
- 11.0
- 35
- 36
Configuration 4
- 35
- 36
No data.
Red Hat Enterprise Linux 6
subversion
Out of support scope
Red Hat Enterprise Linux 7
subversion
Out of support scope
Red Hat Enterprise Linux 8
subversion:1.10/subversion
Fix deferred
Red Hat Enterprise Linux 8
subversion:1.14/subversion
Fix deferred
Red Hat Enterprise Linux 9
subversion
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | subversion | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | subversion | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | subversion:1.10/subversion | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | subversion:1.14/subversion | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | subversion | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- http://seclists.org/fulldisclosure/2022/Jul/18 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-28544 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2074780 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-15220 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZ4ARNGLMGYBKYDX2B7DRBNMF6EH3A6R/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJPMCWCGWBN3QWCDVILWQWPC75RR67LT/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-28544
- https://subversion.apache.org/security/CVE-2021-28544-advisory.txt x_refsource_MISCExploitPatchVendor Advisory
- https://support.apple.com/kb/HT213345 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-28544
- https://www.debian.org/security/2022/dsa-5119 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data