CVE-2021-28544
published 2022-04-12CVE-2021-28544: Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
2.79%
84.8th percentile
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.14.1-3+deb11u1 | 1.14.1-3+deb11u1 |
| apache | subversion | >= 0 < 1.14.2-1 | 1.14.2-1 |
| apache | subversion | >= 0 < 1.14.2-1 | 1.14.2-1 |
| apache | subversion | >= 0 < 1.14.2-1 | 1.14.2-1 |
| apache | subversion | >= 0 < 1.13.0-3ubuntu0.1 | 1.13.0-3ubuntu0.1 |
| apache | subversion | >= 0 < 1.14.1-3ubuntu0.22.04.1 | 1.14.1-3ubuntu0.22.04.1 |
| apache | subversion | 1.10.0 – 1.14.1 | — |
| apache_software_foundation | apache_subversion | — | — |
| apple | macos | >= 12.0 < 12.5 | 12.5 |
| apple | macos_monterey | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | subversion | < subversion 1.14.2-1 (bookworm) | subversion 1.14.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_subversion_1.14.2-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_subversion_1.14.0-5_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-28544: macOS Monterey 12.5
vendor_apple·2022-07-20·CVSS 4.3
CVE-2021-28544 [MEDIUM] CVE-2021-28544: macOS Monterey 12.5
Apple Security Update: About the security content of macOS Monterey 12.5
Product: macOS Monterey
Version: 12.5
CVE: CVE-2021-28544
Component: Spotlight
Impact: An app may be able to gain root privileges
Description: This issue was addressed with improved checks.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2022-05-27·CVSS 4.3
CVE-2021-28544 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in subversion.
Evgeny Kotkov discovered that subversion servers did not properly follow
path-based authorization rules in certain cases. An attacker could
potentially use this issue to retrieve information about private paths.
(CVE-2021-28544)
Thomas Weißschuh discovered that subversion servers did not properly handle
memory in certain configurations. A remote attacker could potentially use
this issue to cause a denial of service or other unspecified impact.
(CVE-2022-24070)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2022-04-12·CVSS 4.3
CVE-2021-28544 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Evgeny Kotkov discovered that Subversion servers did not properly follow
path-based authorization rules in certain cases. An attacker could
potentially use this issue to retrieve information about private paths.
(CVE-2021-28544)
Thomas Weißschuh discovered that Subversion servers did not properly handle
memory in certain configurations. A remote attacker could potentially use
this issue to cause a denial of service or other unspecified impact.
(CVE-2022-24070)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Apache Subversion SVN authz protected copyfrom paths regression
vendor_msrc·2022-04-12·CVSS 4.3
CVE-2021-28544 [MEDIUM] CWE-200 Apache Subversion SVN authz protected copyfrom paths regression
Apache Subversion SVN authz protected copyfrom paths regression
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: htt
Red Hat
subversion: SVN authz protected copyfrom paths regression
vendor_redhat·2022-03-27·CVSS 4.3
CVE-2021-28544 [MEDIUM] CWE-212 subversion: SVN authz protected copyfrom paths regression
subversion: SVN authz protected copyfrom paths regression
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
A flaw was found in Subversion. When using path-based authorization (authz), the helper function detect_changed() does not omit potentially sensitive information from log messages. In particular, if a node is copied from a protected location, its 'copyfrom' pa
Debian
CVE-2021-28544: subversion - Apache Subversion SVN authz protected copyfrom paths regression Subversion serve...
vendor_debian·2021·CVSS 4.3
CVE-2021-28544 [MEDIUM] CVE-2021-28544: subversion - Apache Subversion SVN authz protected copyfrom paths regression Subversion serve...
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
Scope: local
bookworm: resolved (fixed in 1.14.2-1)
bullseye: resolved (fixed in 1.14.1-3+deb11u1)
forky: resolved (fixed in 1.14.2-1)
sid: resolved (fixed in 1.14.2-1)
trixie: resolved (fixed in 1.14.2-1)
Apache
Apache subversion: CVE-2021-28544
vendor_apache·CVSS 4.3
CVE-2021-28544 [MEDIUM] Apache subversion: CVE-2021-28544
Apache subversion: CVE-2021-28544
-advisory.txt [ PGP ] 1.10.0-1.10.7, 1.14.0-1.14.1 SVN authz protected copyfrom paths regression
OSV
subversion vulnerabilities
osv·2022-05-27·CVSS 4.3
CVE-2021-28544 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Evgeny Kotkov discovered that subversion servers did not properly follow
path-based authorization rules in certain cases. An attacker could
potentially use this issue to retrieve information about private paths.
(CVE-2021-28544)
Thomas Weißschuh discovered that subversion servers did not properly handle
memory in certain configurations. A remote attacker could potentially use
this issue to cause a denial of service or other unspecified impact.
(CVE-2022-24070)
GHSA
GHSA-q36f-8454-r4h2: Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configur
ghsa_unreviewed·2022-04-13
CVE-2021-28544 [MEDIUM] CWE-200 GHSA-q36f-8454-r4h2: Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configur
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
OSV
CVE-2021-28544: Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configur
osv·2022-04-12·CVSS 4.3
CVE-2021-28544 [MEDIUM] CVE-2021-28544: Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configur
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
OSV
subversion vulnerabilities
osv·2022-04-12·CVSS 4.3
CVE-2021-28544 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Evgeny Kotkov discovered that Subversion servers did not properly follow
path-based authorization rules in certain cases. An attacker could
potentially use this issue to retrieve information about private paths.
(CVE-2021-28544)
Thomas Weißschuh discovered that Subversion servers did not properly handle
memory in certain configurations. A remote attacker could potentially use
this issue to cause a denial of service or other unspecified impact.
(CVE-2022-24070)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/Jul/18https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZ4ARNGLMGYBKYDX2B7DRBNMF6EH3A6R/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJPMCWCGWBN3QWCDVILWQWPC75RR67LT/https://subversion.apache.org/security/CVE-2021-28544-advisory.txthttps://support.apple.com/kb/HT213345https://www.debian.org/security/2022/dsa-5119http://seclists.org/fulldisclosure/2022/Jul/18https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZ4ARNGLMGYBKYDX2B7DRBNMF6EH3A6R/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJPMCWCGWBN3QWCDVILWQWPC75RR67LT/https://subversion.apache.org/security/CVE-2021-28544-advisory.txthttps://support.apple.com/kb/HT213345https://www.debian.org/security/2022/dsa-5119
2022-04-12
Published