PT-2007-3773 · Apache · Subversion+1
Published
2007-06-14
·
Updated
2024-06-15
·
CVE-2007-2448
CVSS v2.0
2.1
Low
| Vector | AV:N/AC:H/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Subversion versions 1.4.3 and earlier
Description
The issue allows remote authenticated users to obtain sensitive information, specifically revision properties, due to improper implementation of the "partial access" privilege. This can be achieved via
svn commands such as propget, proplist, or propedit.Recommendations
For Subversion versions 1.4.3 and earlier, update to a version that properly implements the "partial access" privilege to prevent unauthorized access to sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Subversion
Subversion