CVE-2004-1438Subversion vulnerability

5 documents5 sources
Severity
2.1LOWNVD
EPSS
0.2%
top 52.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 29

Description

The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

Debianapache/subversion< 1.0.6-1+3
NVDsubversion/subversion6 versions+5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-w39v-wcwg-3989: The mod_authz_svn Apache module for Subversion 12022-04-29
CVEList
CVE-2004-1438: The mod_authz_svn Apache module for Subversion 12005-02-13
OSV
CVE-2004-1438: The mod_authz_svn Apache module for Subversion 12004-12-31

📋Vendor Advisories

1
Debian
CVE-2004-1438: subversion - The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remot...2004
CVE-2004-1438 — Subversion vulnerability | cvebase