Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2022/Jul/18 | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZ4ARNGLMGYBKYDX2B7DRBNMF6EH3A6R/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJPMCWCGWBN3QWCDVILWQWPC75RR67LT/ | Mailing List Third Party Advisory |
https://subversion.apache.org/security/CVE-2021-28544-advisory.txt | Exploit Patch Vendor Advisory |
https://support.apple.com/kb/HT213345 | Third Party Advisory |
https://www.debian.org/security/2022/dsa-5119 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apache
Published: 2022-04-12T17:50:13
Updated: 2022-12-20T13:11:27.211Z
Reserved: 2021-03-16T00:00:00
Link: CVE-2021-28544
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-04-12T18:15:08.250
Modified: 2023-02-11T17:44:50.733
Link: CVE-2021-28544
JSON object: View
Redhat Information
No data.
CWE