CVE-2013-4505
published 2013-12-07CVE-2013-4505: The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended…
PriorityP418low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
7.86%
94.1th percentile
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_apache2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cr4v-cvvq-g798: The is_this_legal function in mod_dontdothat for Apache Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2013-4505 [LOW] GHSA-cr4v-cvvq-g798: The is_this_legal function in mod_dontdothat for Apache Subversion 1
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
OSV
CVE-2013-4505: The is_this_legal function in mod_dontdothat for Apache Subversion 1
osv·2013-12-07·CVSS 2.6
CVE-2013-4505 [LOW] CVE-2013-4505: The is_this_legal function in mod_dontdothat for Apache Subversion 1
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
Red Hat
subversion: mod_dontdothat does not block requests from certain clients
vendor_redhat·2013-11-25·CVSS 2.6
CVE-2013-4505 [LOW] subversion: mod_dontdothat does not block requests from certain clients
subversion: mod_dontdothat does not block requests from certain clients
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
Statement: Not vulnerable. This issue did not affect the versions of Subversion in Red Hat Enterprise Linux 5 and 6.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4505: subversion - The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through...
vendor_debian·2013·CVSS 2.6
CVE-2013-4505 [LOW] CVE-2013-4505: subversion - The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through...
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
Scope: local
bookworm: resolved (fixed in 1.7.14-1)
bullseye: resolved (fixed in 1.7.14-1)
forky: resolved (fixed in 1.7.14-1)
sid: resolved (fixed in 1.7.14-1)
trixie: resolved (fixed in 1.7.14-1)
Apache
Apache subversion: CVE-2013-4505
vendor_apache·CVSS 2.6
CVE-2013-4505 [LOW] Apache subversion: CVE-2013-4505
Apache subversion: CVE-2013-4505
-advisory.txt 1.4.0-1.7.13 and 1.8.0-1.8.4 mod_dontdothat does not restrict requests from serf based clients
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4505 subversion: mod_dontdothat does not block requests from certain clients
bugzilla·2013-11-25·CVSS 2.6
CVE-2013-4505 [LOW] CVE-2013-4505 subversion: mod_dontdothat does not block requests from certain clients
CVE-2013-4505 subversion: mod_dontdothat does not block requests from certain clients
It was found that mod_dontdothat did not block requests from certain clients (such as Serf-based clients). This could allow a client to bypass intended mod_dontdothat restrictions and use more resources on the server than expected. This issue affected mod_dontdothat versions 1.4.0 to 1.7.13, and 1.8.0 to 1.8.4. It has been corrected in versions 1.7.14 and 1.8.5.
mod_dontdothat is included in the subversion sources for Red Hat Enterprise Linux 5 and 6; however, it is not built and shipped for those products, leaving them unaffected by this flaw.
Acknowledgements:
Red Hat would like to thank the Apache Subversion project for reporting this issue. Upstream acknowledges Ben Reser as the original reporter.
Bugzilla
CVE-2013-4505 CVE-2013-4558 subversion: various flaws [fedora-all]
bugzilla·2013-11-25·CVSS 2.6
CVE-2013-4505 [LOW] CVE-2013-4505 CVE-2013-4558 subversion: various flaws [fedora-all]
CVE-2013-4505 CVE-2013-4558 subversion: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multip
http://lists.opensuse.org/opensuse-updates/2013-12/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00048.htmlhttp://osvdb.org/100364http://secunia.com/advisories/55855http://subversion.apache.org/security/CVE-2013-4505-advisory.txthttp://lists.opensuse.org/opensuse-updates/2013-12/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00048.htmlhttp://osvdb.org/100364http://secunia.com/advisories/55855http://subversion.apache.org/security/CVE-2013-4505-advisory.txt
2013-12-07
Published