VulnerabilityModified
CVE-2009-0240
listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.
LOW 3.5EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- tigris/websvn
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191
- http://secunia.com/advisories/32338Vendor Advisory
- http://secunia.com/advisories/33945
- http://secunia.com/advisories/34191
- http://www.debian.org/security/2009/dsa-1725
- http://www.gentoo.org/security/en/glsa/glsa-200903-20.xml
- http://www.openwall.com/lists/oss-security/2009/01/18/2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48171
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191
- http://secunia.com/advisories/32338Vendor Advisory
- http://secunia.com/advisories/33945
- http://secunia.com/advisories/34191
- http://www.debian.org/security/2009/dsa-1725
- http://www.gentoo.org/security/en/glsa/glsa-200903-20.xml
- http://www.openwall.com/lists/oss-security/2009/01/18/2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48171
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.