Apache · Apache Subversion · CVE-2015-3184
**Name of the Vulnerable Software and Affected Versions**
Apache Subversion versions 1.7.x through 1.7.20
Apache Subversion versions 1.8.x through 1.8.13
**Description**
The issue allows remote anonymous users to read hidden files via the path name due to improper restriction of anonymous access in mod authz svn when using Apache httpd 2.4.x.
**Recommendations**
For Apache Subversion versions 1.7.x through 1.7.20, update to version 1.7.21 or later.
For Apache Subversion versions 1.8.x through 1.8.13, update to version 1.8.14 or later.