cbcvebase.
CVE-2015-3187
published 2015-08-12

CVE-2015-3187: The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote…

PriorityP422medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
6.46%
93.0th percentile
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.

Affected

22 ranges
VendorProductVersion rangeFixed in
apachesubversion<= 1.7.20
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion>= 0 < 1.9.0-11.9.0-1
apachesubversion>= 0 < 1.9.0-11.9.0-1
apachesubversion>= 0 < 1.9.0-11.9.0-1
apachesubversion>= 0 < 1.9.0-11.9.0-1
apachesubversion>= 0 < 1.8.8-1ubuntu3.21.8.8-1ubuntu3.2
applexcode<= 7.2.1
applexcode
debiansubversion< subversion 1.9.0-1 (bookworm)subversion 1.9.0-1 (bookworm)

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv5.0MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_apache4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.