CVE-2007-2448
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via…
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.
- CVSS 2.0
- 2.1 LOWAV:N/AC:H/Au:S/C:P/I:N/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- subversion/subversion
- Source
- secalert@redhat.com
References
- http://osvdb.org/36070
- http://secunia.com/advisories/43139
- http://securitytracker.com/id?1018237Patch
- http://subversion.tigris.org/security/CVE-2007-2448-advisory.txt
- http://www.securityfocus.com/bid/24463Patch
- http://www.ubuntu.com/usn/USN-1053-1
- http://www.vupen.com/english/advisories/2007/2230
- http://www.vupen.com/english/advisories/2011/0264
- https://issues.rpath.com/browse/RPL-1896
- http://osvdb.org/36070
- http://secunia.com/advisories/43139
- http://securitytracker.com/id?1018237Patch
- http://subversion.tigris.org/security/CVE-2007-2448-advisory.txt
- http://www.securityfocus.com/bid/24463Patch
- http://www.ubuntu.com/usn/USN-1053-1
- http://www.vupen.com/english/advisories/2007/2230
- http://www.vupen.com/english/advisories/2011/0264
- https://issues.rpath.com/browse/RPL-1896
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.