CVE-2021-28544

medium

Description

Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.

References

https://subversion.apache.org/security/CVE-2021-28544-advisory.txt

https://www.debian.org/security/2022/dsa-5119

https://lists.fedoraproject.org/archives/list/[email protected]/message/YJPMCWCGWBN3QWCDVILWQWPC75RR67LT/

https://lists.fedoraproject.org/archives/list/[email protected]/message/PZ4ARNGLMGYBKYDX2B7DRBNMF6EH3A6R/

https://support.apple.com/kb/HT213345

http://seclists.org/fulldisclosure/2022/Jul/18

Details

Source: MITRE

Published: 2022-04-12

Updated: 2022-07-22

Type: CWE-863

Risk Information

CVSS v2

Base Score: 3.5

Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 6.8

Severity: LOW

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Impact Score: 1.4

Exploitability Score: 2.8

Severity: MEDIUM