CVE-2021-28544

CVE-2021-28544: Apache Subversion SVN authz protected copyfrom paths regression

Vendor Apache Software Foundation
Product Apache Subversion
Weakness CWE-200 · Info exposure
Published April 12, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

Description

Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.

Key dates

Disclosure timeline

April 12, 2022 CVE published
August 3, 2024 Record updated