cbcvebase.
CVE-2010-3315
published 2010-10-04

CVE-2010-3315: authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz…

medium6CVSS 3.1
AVNACMAuSCPIPAP
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion>= 0 < 1.6.12dfsg-21.6.12dfsg-2
apachesubversion>= 0 < 1.6.12dfsg-21.6.12dfsg-2
apachesubversion>= 0 < 1.6.12dfsg-21.6.12dfsg-2

CVSS provenance

nvd6.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM