Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kamesh Jayachandran

Researcher fromCollabNet, Inc.
#22151of 53,633
10.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2011-3477
4.3
2011-06-06
Apache · Apache Subversion · CVE-2011-1921
**Name of the Vulnerable Software and Affected Versions** Apache Subversion versions 1.5.x through 1.6.16 **Description** The issue allows remote attackers to obtain sensitive information via a replay REPORT operation, due to improper permission enforcement for files that had been publicly readable in the past when the SVNPathAuthz short circuit option is disabled. **Recommendations** For Apache Subversion versions 1.5.x through 1.6.16, update to version 1.6.17 or later to resolve the issue.
PT-2010-4727
6.0
2010-10-04
Apache · Apache Subversion · CVE-2010-3315
**Name of the Vulnerable Software and Affected Versions** Apache Subversion versions 1.5.x through 1.5.7 Apache Subversion versions 1.6.x through 1.6.12 **Description** The issue allows remote authenticated users to bypass intended access restrictions via svn commands, due to improper handling of a named repository as a rule scope in the mod dav svn module when SVNPathAuthz short circuit is enabled. **Recommendations** For Apache Subversion versions 1.5.x through 1.5.7, update to version 1.5.8 or later. For Apache Subversion versions 1.6.x through 1.6.12, update to version 1.6.13 or later.