PT-2011-3477 · Apache+1 · Apache Subversion+1

Kamesh Jayachandran

·

Published

2011-06-06

·

Updated

2024-06-15

·

CVE-2011-1921

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Subversion versions 1.5.x through 1.6.16
Description The issue allows remote attackers to obtain sensitive information via a replay REPORT operation, due to improper permission enforcement for files that had been publicly readable in the past when the SVNPathAuthz short circuit option is disabled.
Recommendations For Apache Subversion versions 1.5.x through 1.6.16, update to version 1.6.17 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1921
DSA-2251-1
OPENSUSE-SU-2024:10538-1
RHSA-2011:0862
RHSA-2011_0862

Affected Products

Apache Subversion
Red Hat