Vulnerability Name: | CVE-2004-0749 (CCN-17472) | ||||||||
Assigned: | 2004-09-23 | ||||||||
Published: | 2004-09-23 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-0749 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2004:883 Fixes for subverion's vulnerabilities Source: FEDORA Type: UNKNOWN FEDORA-2004-318 Source: CCN Type: Subversion Web site mod_authz_svn fails to protect metadata Source: CONFIRM Type: Patch, Vendor Advisory http://subversion.tigris.org/security/CAN-2004-0749-advisory.txt Source: CCN Type: GLSA-200409-35 Subversion: Metadata information leak Source: GENTOO Type: Patch, Vendor Advisory GLSA-200409-35 Source: CCN Type: OSVDB ID: 10217 Subversion (SVN) mod_authz_svn Unreadable Path Metadata Information Disclosure Source: BID Type: Patch, Vendor Advisory 11243 Source: CCN Type: BID-11243 Subversion Mod_Authz_Svn Metadata Information Disclosure Vulnerability Source: XF Type: UNKNOWN subversion-information-disclosure(17472) Source: XF Type: UNKNOWN subversion-information-disclosure(17472) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |