Severity
6.5MEDIUM
EPSS
1.2%
top 21.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 26
Latest updateMay 26

Description

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDapache/subversion1.10.01.10.4+3
CVEListV5apache_subversionApache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0
Debiansubversion< 1.10.6-1+3
Ubuntusubversion< 1.9.3-2ubuntu1.3+2

Patches

🔴Vulnerability Details

5
OSV
subversion vulnerabilities2022-05-26
GHSA
GHSA-mggm-8657-6fhf: In Apache Subversion versions up to and including 12022-05-24
OSV
CVE-2018-11782: In Apache Subversion versions up to and including 12019-09-26
CVEList
CVE-2018-11782: In Apache Subversion versions up to and including 12019-09-26
OSV
subversion vulnerabilities2019-07-31

📋Vendor Advisories

6
Ubuntu
Subversion vulnerabilities2022-05-26
Ubuntu
Subversion vulnerabilities2019-07-31
Ubuntu
Subversion vulnerabilities2019-07-31
Red Hat
subversion: remotely triggerable DoS vulnerability in svnserve 'get-deleted-rev'2019-07-31
Debian
CVE-2018-11782: subversion - In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subver...2018

💬Community

2
Bugzilla
CVE-2018-11782 subversion: remotely triggerable DoS vulnerability in svnserve 'get-deleted-rev' [fedora-all]2019-08-01
Bugzilla
CVE-2018-11782 subversion: remotely triggerable DoS vulnerability in svnserve 'get-deleted-rev'2019-07-25
CVE-2018-11782 (MEDIUM CVSS 6.5) | In Apache Subversion versions up to | cvebase.io