CVE-2015-3187
subversion: svn_repos_trace_node_locations() reveals paths hidden by authz
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.
Vulnerabilidad en la función svn_repos_trace_node_locations en Apache Subversion en versiones anteriores a 1.7.21 y 1.8.x en versiones anteriores a 1.8.14, cuando se utiliza autorización basada en ruta, permite a usuarios remotos autenticados obtener información de ruta sensible leyendo el historial de un nodo que ha sido movido desde una ruta oculta.
It was found that when an SVN server (both svnserve and httpd with the mod_dav_svn module) searched the history of a file or a directory, it would disclose its location in the repository if that file or directory was not readable (for example, if it had been moved).
It was discovered that the Subversion mod_dav_svn module incorrectly handled REPORT requests for a resource that does not exist. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. It was discovered that the Subversion mod_dav_svn module incorrectly handled requests requiring a lookup for a virtual transaction name that does not exist. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-04-10 CVE Reserved
- 2015-08-12 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/76273 | Vdb Entry | |
http://www.securitytracker.com/id/1033215 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.html | 2017-07-01 | |
http://lists.opensuse.org/opensuse-updates/2015-08/msg00022.html | 2017-07-01 | |
http://rhn.redhat.com/errata/RHSA-2015-1633.html | 2017-07-01 | |
http://rhn.redhat.com/errata/RHSA-2015-1742.html | 2017-07-01 | |
http://subversion.apache.org/security/CVE-2015-3187-advisory.txt | 2017-07-01 | |
http://www.debian.org/security/2015/dsa-3331 | 2017-07-01 | |
http://www.ubuntu.com/usn/USN-2721-1 | 2017-07-01 | |
https://security.gentoo.org/glsa/201610-05 | 2017-07-01 | |
https://support.apple.com/HT206172 | 2017-07-01 | |
https://access.redhat.com/security/cve/CVE-2015-3187 | 2015-09-08 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1247252 | 2015-09-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | <= 1.7.20 Search vendor "Apache" for product "Subversion" and version " <= 1.7.20" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.1 Search vendor "Apache" for product "Subversion" and version "1.8.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.2 Search vendor "Apache" for product "Subversion" and version "1.8.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.3 Search vendor "Apache" for product "Subversion" and version "1.8.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.4 Search vendor "Apache" for product "Subversion" and version "1.8.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.5 Search vendor "Apache" for product "Subversion" and version "1.8.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.6 Search vendor "Apache" for product "Subversion" and version "1.8.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.7 Search vendor "Apache" for product "Subversion" and version "1.8.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.8 Search vendor "Apache" for product "Subversion" and version "1.8.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.9 Search vendor "Apache" for product "Subversion" and version "1.8.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.10 Search vendor "Apache" for product "Subversion" and version "1.8.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.11 Search vendor "Apache" for product "Subversion" and version "1.8.11" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.8.13 Search vendor "Apache" for product "Subversion" and version "1.8.13" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Xcode Search vendor "Apple" for product "Xcode" | <= 7.2.1 Search vendor "Apple" for product "Xcode" and version " <= 7.2.1" | - |
Affected
|