VulnerabilityModified
CVE-2015-3184
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
MEDIUM 5.0EPSS 10.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 10.61% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/xcode · apache/subversion
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2015-08/msg00022.html
- http://rhn.redhat.com/errata/RHSA-2015-1742.html
- http://subversion.apache.org/security/CVE-2015-3184-advisory.txtVendor Advisory
- http://www.debian.org/security/2015/dsa-3331
- http://www.securityfocus.com/bid/76274
- http://www.securitytracker.com/id/1033215
- http://www.ubuntu.com/usn/USN-2721-1
- https://security.gentoo.org/glsa/201610-05
- https://support.apple.com/HT206172Vendor Advisory
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2015-08/msg00022.html
- http://rhn.redhat.com/errata/RHSA-2015-1742.html
- http://subversion.apache.org/security/CVE-2015-3184-advisory.txtVendor Advisory
- http://www.debian.org/security/2015/dsa-3331
- http://www.securityfocus.com/bid/76274
- http://www.securitytracker.com/id/1033215
- http://www.ubuntu.com/usn/USN-2721-1
- https://security.gentoo.org/glsa/201610-05
- https://support.apple.com/HT206172Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.