CVE-2015-3184
published 2015-08-12CVE-2015-3184: mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access…
PriorityP335medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
10.61%
95.3th percentile
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_apache5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrec
Red Hat
subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4
vendor_redhat·2015-08-05·CVSS 5.0
CVE-2015-3184 [MEDIUM] CWE-285 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4
subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
It was found that the mod_authz_svn module did not properly restrict anonymous access to Subversion repositories under certain configurations when used with Apache httpd 2.4.x. This could allow a user to anonymously access files in a Subversion repository, which should only be accessible to authenticated users.
Statement: This issue did not affect versions of subversion as shipped with Red Hat Enterprise Linux 5 and 6.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Pa
Debian
CVE-2015-3184: subversion - mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, ...
vendor_debian·2015·CVSS 5.0
CVE-2015-3184 [MEDIUM] CVE-2015-3184: subversion - mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, ...
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
Scope: local
bookworm: resolved (fixed in 1.9.0-1)
bullseye: resolved (fixed in 1.9.0-1)
forky: resolved (fixed in 1.9.0-1)
sid: resolved (fixed in 1.9.0-1)
trixie: resolved (fixed in 1.9.0-1)
Apache
Apache subversion: CVE-2015-3184
vendor_apache·CVSS 5.0
CVE-2015-3184 [MEDIUM] Apache subversion: CVE-2015-3184
Apache subversion: CVE-2015-3184
-advisory.txt 1.7.0-1.7.20 and 1.8.0-1.8.13 Subversion's mod_authz_svn does not properly restrict anonymous access in some mixed anonymous/authenticated environments when using Apache httpd 2.4.
Apple
CVE-2015-3184: Xcode 7.3
vendor_apple·CVSS 5.0
CVE-2015-3184 [MEDIUM] CVE-2015-3184: Xcode 7.3
Apple Security Update: About the security content of Xcode 7.3
Product: Xcode
Version: 7.3
CVE: CVE-2015-3184
Component: CVE-ID
GHSA
GHSA-8578-652m-fxc9: mod_authz_svn in Apache Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2015-3184 [MEDIUM] CWE-200 GHSA-8578-652m-fxc9: mod_authz_svn in Apache Subversion 1
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
OSV
subversion vulnerabilities
osv·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrectly
handled large numbers of REPORT requests. A remote attacker cou
OSV
CVE-2015-3184: mod_authz_svn in Apache Subversion 1
osv·2015-08-12·CVSS 5.0
CVE-2015-3184 [MEDIUM] CVE-2015-3184: mod_authz_svn in Apache Subversion 1
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3184 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4 [fedora-all]
bugzilla·2015-08-06·CVSS 5.0
CVE-2015-3184 [MEDIUM] CVE-2015-3184 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4 [fedora-all]
CVE-2015-3184 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2015-3184 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4
bugzilla·2015-07-27·CVSS 5.0
CVE-2015-3184 [MEDIUM] CVE-2015-3184 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4
CVE-2015-3184 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4
Below is the upstream report about a security issue in Subversion:
Summary
Subversion's mod_authz_svn does not properly restrict anonymous
access in some mixed anonymous/authenticated environments when using
Apache httpd 2.4. The result is that anonymous access may be possible
to files for which only authenticated access should be possible.
Known vulnerable
CVE-2015-3185 Apache httpd 2.4.0 to 2.4.12
CVE-2015-3184 Apache Subversion 1.8.0 to 1.8.13
CVE-2015-3184 Apache Subversion 1.7.0 to 1.7.20
Servers are vulnerable if either httpd or Subversion is as listed.
Subversion 1.6 does not build with httpd 2.4 and servers using
httpd 2.2 are not vulnerable. Servers that are configured to deny
anonymous
http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2015-08/msg00022.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1742.htmlhttp://subversion.apache.org/security/CVE-2015-3184-advisory.txthttp://www.debian.org/security/2015/dsa-3331http://www.securityfocus.com/bid/76274http://www.securitytracker.com/id/1033215http://www.ubuntu.com/usn/USN-2721-1https://security.gentoo.org/glsa/201610-05https://support.apple.com/HT206172http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2015-08/msg00022.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1742.htmlhttp://subversion.apache.org/security/CVE-2015-3184-advisory.txthttp://www.debian.org/security/2015/dsa-3331http://www.securityfocus.com/bid/76274http://www.securitytracker.com/id/1033215http://www.ubuntu.com/usn/USN-2721-1https://security.gentoo.org/glsa/201610-05https://support.apple.com/HT206172
2015-08-12
Published