CVE-2021-28544
Both httpd and svnserve servers are vulnerable.
Does this matter?
Lower severity and a low EPSS score (2.79%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.79% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apache/subversion · debian/debian linux · fedoraproject/fedora · apple/macos
- Source
- security@apache.org
References
- http://seclists.org/fulldisclosure/2022/Jul/18Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZ4ARNGLMGYBKYDX2B7DRBNMF6EH3A6R/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJPMCWCGWBN3QWCDVILWQWPC75RR67LT/Mailing List, Third Party Advisory
- https://subversion.apache.org/security/CVE-2021-28544-advisory.txtExploit, Patch, Vendor Advisory
- https://support.apple.com/kb/HT213345Third Party Advisory
- https://www.debian.org/security/2022/dsa-5119Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jul/18Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZ4ARNGLMGYBKYDX2B7DRBNMF6EH3A6R/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJPMCWCGWBN3QWCDVILWQWPC75RR67LT/Mailing List, Third Party Advisory
- https://subversion.apache.org/security/CVE-2021-28544-advisory.txtExploit, Patch, Vendor Advisory
- https://support.apple.com/kb/HT213345Third Party Advisory
- https://www.debian.org/security/2022/dsa-5119Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.