Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kamesh Jayachandran

Pesquisador deCollabNet, Inc.
#22208de 53,779
10.3CVSS total
Vulnerabilidades · 2
Média
2
PT-2011-3477
4.3
2011-06-06
Apache · Apache Subversion · CVE-2011-1921
**Name of the Vulnerable Software and Affected Versions** Apache Subversion versions 1.5.x through 1.6.16 **Description** The issue allows remote attackers to obtain sensitive information via a replay REPORT operation, due to improper permission enforcement for files that had been publicly readable in the past when the SVNPathAuthz short circuit option is disabled. **Recommendations** For Apache Subversion versions 1.5.x through 1.6.16, update to version 1.6.17 or later to resolve the issue.
PT-2010-4727
6.0
2010-10-04
Apache · Apache Subversion · CVE-2010-3315
**Name of the Vulnerable Software and Affected Versions** Apache Subversion versions 1.5.x through 1.5.7 Apache Subversion versions 1.6.x through 1.6.12 **Description** The issue allows remote authenticated users to bypass intended access restrictions via svn commands, due to improper handling of a named repository as a rule scope in the mod dav svn module when SVNPathAuthz short circuit is enabled. **Recommendations** For Apache Subversion versions 1.5.x through 1.5.7, update to version 1.5.8 or later. For Apache Subversion versions 1.6.x through 1.6.12, update to version 1.6.13 or later.