CVE-2011-1921
published 2011-06-06CVE-2011-1921: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
5.99%
92.5th percentile
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2011-06-06·CVSS 5.0
CVE-2011-1752 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: An attacker could send crafted input to the Subversion mod_dav_svn module
for Apache and cause it to crash or gain access to restricted files.
Joe Schaefer discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain baselined WebDAV resource requests. A
remote attacker could use this flaw to cause the service to crash, leading
to a denial of service. (CVE-2011-1752)
Ivan Zhakov discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain requests. A remote attacker could use this
flaw to cause the service to consume all available resources, leading to a
denial of service. (CVE-2011-1783)
Kamesh Jayachandran discovered that the Subversion mod_dav_svn module for
Apache did not prop
Red Hat
(mod_dav_svn): File contents disclosure of files configured to be unreadable by those users
vendor_redhat·2011-06-01·CVSS 4.3
CVE-2011-1921 [MEDIUM] (mod_dav_svn): File contents disclosure of files configured to be unreadable by those users
(mod_dav_svn): File contents disclosure of files configured to be unreadable by those users
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
Package: subversion (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2011-1921: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv...
vendor_debian·2011·CVSS 4.3
CVE-2011-1921 [MEDIUM] CVE-2011-1921: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv...
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
Scope: local
bookworm: resolved (fixed in 1.6.17dfsg-1)
bullseye: resolved (fixed in 1.6.17dfsg-1)
forky: resolved (fixed in 1.6.17dfsg-1)
sid: resolved (fixed in 1.6.17dfsg-1)
trixie: resolved (fixed in 1.6.17dfsg-1)
Apache
Apache subversion: CVE-2011-1921
vendor_apache·CVSS 4.3
CVE-2011-1921 [MEDIUM] Apache subversion: CVE-2011-1921
Apache subversion: CVE-2011-1921
-advisory.txt 1.5.0-1.6.16 mod_dav_svn exposure of unreadable paths
GHSA
GHSA-jcxf-qq8g-jpph: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2011-1921 [MEDIUM] GHSA-jcxf-qq8g-jpph: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
OSV
CVE-2011-1921: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1
osv·2011-06-06·CVSS 4.3
CVE-2011-1921 [MEDIUM] CVE-2011-1921: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
bugzilla·2011-06-02·CVSS 5.0
CVE-2011-1752 [MEDIUM] CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=709111
Please note: this issue affects mul
Bugzilla
CVE-2011-1921 subversion (mod_dav_svn): File contents disclosure of files configured to be unreadable by those users
bugzilla·2011-05-30·CVSS 4.3
CVE-2011-1921 [MEDIUM] CVE-2011-1921 subversion (mod_dav_svn): File contents disclosure of files configured to be unreadable by those users
CVE-2011-1921 subversion (mod_dav_svn): File contents disclosure of files configured to be unreadable by those users
An unintended file contents disclosure flaw was found in the way mod_dav_svn
module of the subversion concurrent version control system processed certain
URLs, when path-access control for files and directories was enabled. A
remote attacker could use this flaw to obtain information, which should
be otherwise prohibited by the authorization subsystem.
Acknowledgements:
Red Hat would like to thank the Apache Subversion project for reporting this
issue. Upstream acknowledges Kamesh Jayachandran of CollabNet, Inc. as the
original reporter.
Discussion:
This issue did NOT affect the version of the subversion package, as shipped
with Red Hat Enterprise Linux 4.
--
This issu
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.htmlhttp://secunia.com/advisories/44633http://secunia.com/advisories/44681http://secunia.com/advisories/44849http://secunia.com/advisories/44888http://secunia.com/advisories/45162http://subversion.apache.org/security/CVE-2011-1921-advisory.txthttp://support.apple.com/kb/HT5130http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGEShttp://www.debian.org/security/2011/dsa-2251http://www.mandriva.com/security/advisories?name=MDVSA-2011:106http://www.redhat.com/support/errata/RHSA-2011-0862.htmlhttp://www.securityfocus.com/bid/48091http://www.securitytracker.com/id?1025619http://www.ubuntu.com/usn/USN-1144-1https://bugzilla.redhat.com/show_bug.cgi?id=709114https://exchange.xforce.ibmcloud.com/vulnerabilities/67804https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18999http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.htmlhttp://secunia.com/advisories/44633http://secunia.com/advisories/44681http://secunia.com/advisories/44849http://secunia.com/advisories/44888http://secunia.com/advisories/45162http://subversion.apache.org/security/CVE-2011-1921-advisory.txthttp://support.apple.com/kb/HT5130http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGEShttp://www.debian.org/security/2011/dsa-2251http://www.mandriva.com/security/advisories?name=MDVSA-2011:106http://www.redhat.com/support/errata/RHSA-2011-0862.htmlhttp://www.securityfocus.com/bid/48091http://www.securitytracker.com/id?1025619http://www.ubuntu.com/usn/USN-1144-1https://bugzilla.redhat.com/show_bug.cgi?id=709114https://exchange.xforce.ibmcloud.com/vulnerabilities/67804https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18999
2011-06-06
Published