SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4558

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a…

LOW 3.5EPSS 5.88%

Does this matter?

Lower severity and a low EPSS score (5.88%). Track it; it rarely justifies an emergency change on its own.

Description

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.

CVSS 2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
EPSS
5.88% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
apache/mod dav svn · apache/subversion
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.