CVE-2020-17525
published 2021-03-17CVE-2020-17525: Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client…
PriorityP354high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
40.08%
98.5th percentile
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.14.1-1 | 1.14.1-1 |
| apache | subversion | >= 0 < 1.14.1-1 | 1.14.1-1 |
| apache | subversion | >= 0 < 1.14.1-1 | 1.14.1-1 |
| apache | subversion | >= 0 < 1.14.1-1 | 1.14.1-1 |
| apache | subversion | >= 0 < 1.9.7-4ubuntu1.1 | 1.9.7-4ubuntu1.1 |
| apache | subversion | >= 0 < 1.13.0-3ubuntu0.2 | 1.13.0-3ubuntu0.2 |
| apache | subversion | >= 1.11.0 < 1.14.1 | 1.14.1 |
| apache | subversion | >= 1.9.0 < 1.10.7 | 1.10.7 |
| apache_software_foundation | apache_subversion | >= mod_authz_svn < 1.14.1 | 1.14.1 |
| debian | debian_linux | — | — |
| debian | subversion | < subversion 1.14.1-1 (bookworm) | subversion 1.14.1-1 (bookworm) |
| msrc | cbl2_subversion_1.14.0-4_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_subversion_1.14.0-4_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2022-05-26·CVSS 6.5
CVE-2020-17525 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in subversion.
Ace Olszowka discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to cause
svnserver to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-11782)
Tomas Bortoli discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to cause
svnserver to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2019-0203)
Thomas Åkesson discovered that Subversion incorrectly handled certain
inputs. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-17525)
Instructions: In ge
Ubuntu
Subversion vulnerability
vendor_ubuntu·2022-03-10
CVE-2020-17525 Subversion vulnerability
Title: Subversion vulnerability
Summary: Subversion could be made to crash if it received specially crafted input.
Thomas Akesson discovered that Subversion incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Remote unauthenticated denial-of-service in Subversion mod_authz_svn
vendor_msrc·2021-03-09·CVSS 7.5
CVE-2020-17525 [HIGH] CWE-476 Remote unauthenticated denial-of-service in Subversion mod_authz_svn
Remote unauthenticated denial-of-service in Subversion mod_authz_svn
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference
Red Hat
subversion: Remote unauthenticated denial of service in mod_authz_svn
vendor_redhat·2021-02-10·CVSS 7.5
CVE-2020-17525 [HIGH] CWE-416 subversion: Remote unauthenticated denial of service in mod_authz_svn
subversion: Remote unauthenticated denial of service in mod_authz_svn
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
A null-pointer-dereference flaw was found in mod_authz_svn of subversion. This flaw allows a remote, unauthenticated attacker to cause a denial of service in some server configurations. The highest threat from this vulnerability is to system availability.
Mitigation: As per upstream "As a workaround, the use of in-repository authz rules files with the Aut
Debian
CVE-2020-17525: subversion - Subversion's mod_authz_svn module will crash if the server is using in-repositor...
vendor_debian·2020·CVSS 7.5
CVE-2020-17525 [HIGH] CVE-2020-17525: subversion - Subversion's mod_authz_svn module will crash if the server is using in-repositor...
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye: resolved (fixed in 1.14.1-1)
forky: resolved (fixed in 1.14.1-1)
sid: resolved (fixed in 1.14.1-1)
trixie: resolved (fixed in 1.14.1-1)
Apache
Apache subversion: CVE-2020-17525
vendor_apache·CVSS 7.5
CVE-2020-17525 [HIGH] Apache subversion: CVE-2020-17525
Apache subversion: CVE-2020-17525
-advisory.txt [ PGP ] 1.9.0-1.9.10, 1.10.0-1.10.6, 1.11.0-1.11.1, 1.12.0-1.12.2, 1.13.0, 1.14.0 Remote unauthenticated denial-of-service in mod_authz_svn.
OSV
subversion vulnerabilities
osv·2022-05-26·CVSS 6.5
CVE-2018-11782 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Ace Olszowka discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to cause
svnserver to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-11782)
Tomas Bortoli discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to cause
svnserver to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2019-0203)
Thomas Åkesson discovered that Subversion incorrectly handled certain
inputs. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-17525)
GHSA
GHSA-w6m8-jhpf-wj94: Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a cl
ghsa_unreviewed·2022-05-24
CVE-2020-17525 [HIGH] CWE-476 GHSA-w6m8-jhpf-wj94: Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a cl
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
OSV
CVE-2020-17525: Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a cl
osv·2021-03-17·CVSS 7.5
CVE-2020-17525 [HIGH] CVE-2020-17525: Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a cl
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-17
Published