PT-2007-3773 · Apache · Subversion+1
Publicado
2007-06-14
·
Atualizado
2024-06-15
·
CVE-2007-2448
CVSS v2.0
2.1
Baixa
| Vetor | AV:N/AC:H/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Subversion versions 1.4.3 and earlier
Description
The issue allows remote authenticated users to obtain sensitive information, specifically revision properties, due to improper implementation of the "partial access" privilege. This can be achieved via
svn commands such as propget, proplist, or propedit.Recommendations
For Subversion versions 1.4.3 and earlier, update to a version that properly implements the "partial access" privilege to prevent unauthorized access to sensitive information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Subversion
Subversion