CVE-2010-3315
published 2010-10-04CVE-2010-3315: authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz…
PriorityP337medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
4.22%
89.9th percentile
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.6.12dfsg-2 | 1.6.12dfsg-2 |
| apache | subversion | >= 0 < 1.6.12dfsg-2 | 1.6.12dfsg-2 |
| apache | subversion | >= 0 < 1.6.12dfsg-2 | 1.6.12dfsg-2 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_apache6.0MEDIUM
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2011-02-01·CVSS 2.1
CVE-2007-2448 [LOW] Subversion vulnerabilities
Title: Subversion vulnerabilities
It was discovered that Subversion incorrectly handled certain 'partial
access' privileges in rare scenarios. Remote authenticated users could use
this flaw to obtain sensitive information (revision properties). This issue
only applied to Ubuntu 6.06 LTS. (CVE-2007-2448)
It was discovered that the Subversion mod_dav_svn module for Apache did not
properly handle a named repository as a rule scope. Remote authenticated
users could use this flaw to bypass intended restrictions. This issue only
applied to Ubuntu 9.10, 10.04 LTS, and 10.10. (CVE-2010-3315)
It was discovered that the Subversion mod_dav_svn module for Apache
incorrectly handled the walk function. Remote authenticated users could use
this flaw to cause the service to crash, leading to a denial o
Red Hat
Subversion: Access restriction bypass by checkout of the root of the repository
vendor_redhat·2010-10-04·CVSS 6.0
CVE-2010-3315 [MEDIUM] Subversion: Access restriction bypass by checkout of the root of the repository
Subversion: Access restriction bypass by checkout of the root of the repository
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
Package: subversion (Red Hat Enterprise Linux 4) - Not affected
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2010-3315: subversion - authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in ...
vendor_debian·2010·CVSS 6.0
CVE-2010-3315 [MEDIUM] CVE-2010-3315: subversion - authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in ...
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
Scope: local
bookworm: resolved (fixed in 1.6.12dfsg-2)
bullseye: resolved (fixed in 1.6.12dfsg-2)
forky: resolved (fixed in 1.6.12dfsg-2)
sid: resolved (fixed in 1.6.12dfsg-2)
trixie: resolved (fixed in 1.6.12dfsg-2)
Apache
Apache subversion: CVE-2010-3315
vendor_apache·CVSS 6.0
CVE-2010-3315 [MEDIUM] Apache subversion: CVE-2010-3315
Apache subversion: CVE-2010-3315
-advisory.txt 1.5.0-1.5.7, 1.6.0-1.6.12 mod_dav_svn exposure of unreadable paths when SVNPathAuthz "short_circuit" is employed.
GHSA
GHSA-rwpr-66p9-2829: authz
ghsa_unreviewed·2022-05-17
CVE-2010-3315 [MEDIUM] GHSA-rwpr-66p9-2829: authz
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
OSV
CVE-2010-3315: authz
osv·2010-10-04·CVSS 6.0
CVE-2010-3315 [MEDIUM] CVE-2010-3315: authz
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3315 Subversion: Access restriction bypass by checkout of the root of the repository [fedora-all]
bugzilla·2011-01-25·CVSS 6.0
CVE-2010-3315 [MEDIUM] CVE-2010-3315 Subversion: Access restriction bypass by checkout of the root of the repository [fedora-all]
CVE-2010-3315 Subversion: Access restriction bypass by checkout of the root of the repository [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=640317
Please n
Bugzilla
CVE-2010-3315 Subversion: Access restriction bypass by checkout of the root of the repository
bugzilla·2010-10-05·CVSS 6.0
CVE-2010-3315 [MEDIUM] CVE-2010-3315 Subversion: Access restriction bypass by checkout of the root of the repository
CVE-2010-3315 Subversion: Access restriction bypass by checkout of the root of the repository
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-3315 to
the following vulnerability:
authz.c in the mod_dav_svn module for the Apache HTTP Server, as
distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before
1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly
handle a named repository as a rule scope, which allows remote
authenticated users to bypass intended access restrictions via svn
commands.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3315
[2] http://security-tracker.debian.org/tracker/CVE-2010-3315
[3] http://subversion.apache.org/security/CVE-2010-3315-advisory.txt
[4] http://secunia.com/advisories/41652
Discu
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://secunia.com/advisories/41652http://secunia.com/advisories/43139http://secunia.com/advisories/43346http://security-tracker.debian.org/tracker/CVE-2010-3315http://subversion.apache.org/security/CVE-2010-3315-advisory.txthttp://support.apple.com/kb/HT4581http://www.debian.org/security/2010/dsa-2118http://www.mandriva.com/security/advisories?name=MDVSA-2010:199http://www.redhat.com/support/errata/RHSA-2011-0258.htmlhttp://www.ubuntu.com/usn/USN-1053-1http://www.vupen.com/english/advisories/2011/0264https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19007http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://secunia.com/advisories/41652http://secunia.com/advisories/43139http://secunia.com/advisories/43346http://security-tracker.debian.org/tracker/CVE-2010-3315http://subversion.apache.org/security/CVE-2010-3315-advisory.txthttp://support.apple.com/kb/HT4581http://www.debian.org/security/2010/dsa-2118http://www.mandriva.com/security/advisories?name=MDVSA-2010:199http://www.redhat.com/support/errata/RHSA-2011-0258.htmlhttp://www.ubuntu.com/usn/USN-1053-1http://www.vupen.com/english/advisories/2011/0264https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19007
2010-10-04
Published