SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3528

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication…

MEDIUM 4.0EPSS 7.40%

Does this matter?

Lower severity and a low EPSS score (7.40%). Track it; it rarely justifies an emergency change on its own.

Description

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

CVSS 2.0
4.0 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
EPSS
7.40% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-255
Affected
opensuse/opensuse · apache/subversion · canonical/ubuntu linux · apple/xcode · redhat/enterprise linux desktop · redhat/enterprise linux hpc node · redhat/enterprise linux server · redhat/enterprise linux server eus · redhat/enterprise linux workstation
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.