Lucene search

K
cveRedhatCVE-2014-3528
HistoryAug 19, 2014 - 6:55 p.m.

CVE-2014-3528

2014-08-1918:55:02
CWE-255
redhat
web.nvd.nist.gov
53
cve-2014-3528
apache subversion
md5 hash
vulnerability
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

8.6

Confidence

High

EPSS

0.002

Percentile

57.0%

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

Affected configurations

Nvd
Node
opensuseopensuseMatch12.3
OR
opensuseopensuseMatch13.1
Node
apachesubversionMatch1.0.0
OR
apachesubversionMatch1.0.1
OR
apachesubversionMatch1.0.2
OR
apachesubversionMatch1.0.3
OR
apachesubversionMatch1.0.4
OR
apachesubversionMatch1.0.5
OR
apachesubversionMatch1.0.6
OR
apachesubversionMatch1.0.7
OR
apachesubversionMatch1.0.8
OR
apachesubversionMatch1.0.9
OR
apachesubversionMatch1.1.0
OR
apachesubversionMatch1.1.1
OR
apachesubversionMatch1.1.2
OR
apachesubversionMatch1.1.3
OR
apachesubversionMatch1.1.4
OR
apachesubversionMatch1.2.0
OR
apachesubversionMatch1.2.1
OR
apachesubversionMatch1.2.2
OR
apachesubversionMatch1.2.3
OR
apachesubversionMatch1.3.0
OR
apachesubversionMatch1.3.1
OR
apachesubversionMatch1.3.2
OR
apachesubversionMatch1.4.0
OR
apachesubversionMatch1.4.1
OR
apachesubversionMatch1.4.2
OR
apachesubversionMatch1.4.3
OR
apachesubversionMatch1.4.4
OR
apachesubversionMatch1.4.5
OR
apachesubversionMatch1.4.6
OR
apachesubversionMatch1.5.0
OR
apachesubversionMatch1.5.1
OR
apachesubversionMatch1.5.2
OR
apachesubversionMatch1.5.3
OR
apachesubversionMatch1.5.4
OR
apachesubversionMatch1.5.5
OR
apachesubversionMatch1.5.6
OR
apachesubversionMatch1.5.7
OR
apachesubversionMatch1.5.8
OR
apachesubversionMatch1.6.0
OR
apachesubversionMatch1.6.1
OR
apachesubversionMatch1.6.2
OR
apachesubversionMatch1.6.3
OR
apachesubversionMatch1.6.4
OR
apachesubversionMatch1.6.5
OR
apachesubversionMatch1.6.6
OR
apachesubversionMatch1.6.7
OR
apachesubversionMatch1.6.8
OR
apachesubversionMatch1.6.9
OR
apachesubversionMatch1.6.10
OR
apachesubversionMatch1.6.11
OR
apachesubversionMatch1.6.12
OR
apachesubversionMatch1.6.13
OR
apachesubversionMatch1.6.14
OR
apachesubversionMatch1.6.15
OR
apachesubversionMatch1.6.16
OR
apachesubversionMatch1.6.17
OR
apachesubversionMatch1.6.18
OR
apachesubversionMatch1.6.19
OR
apachesubversionMatch1.6.20
OR
apachesubversionMatch1.6.21
OR
apachesubversionMatch1.6.23
OR
apachesubversionMatch1.7.0
OR
apachesubversionMatch1.7.1
OR
apachesubversionMatch1.7.2
OR
apachesubversionMatch1.7.3
OR
apachesubversionMatch1.7.4
OR
apachesubversionMatch1.7.5
OR
apachesubversionMatch1.7.6
OR
apachesubversionMatch1.7.7
OR
apachesubversionMatch1.7.8
OR
apachesubversionMatch1.7.9
OR
apachesubversionMatch1.7.10
OR
apachesubversionMatch1.7.11
OR
apachesubversionMatch1.7.12
OR
apachesubversionMatch1.7.13
OR
apachesubversionMatch1.7.14
OR
apachesubversionMatch1.7.15
OR
apachesubversionMatch1.7.16
OR
apachesubversionMatch1.7.17
OR
apachesubversionMatch1.8.0
OR
apachesubversionMatch1.8.1
OR
apachesubversionMatch1.8.2
OR
apachesubversionMatch1.8.3
OR
apachesubversionMatch1.8.4
OR
apachesubversionMatch1.8.5
OR
apachesubversionMatch1.8.6
OR
apachesubversionMatch1.8.7
OR
apachesubversionMatch1.8.8
OR
apachesubversionMatch1.8.9
Node
canonicalubuntu_linuxMatch12.04-lts
OR
canonicalubuntu_linuxMatch14.04lts
Node
applexcodeMatch6.1.1
Node
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_desktopMatch7.0
OR
redhatenterprise_linux_hpc_nodeMatch6.0
OR
redhatenterprise_linux_hpc_nodeMatch7.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_serverMatch7.0
OR
redhatenterprise_linux_server_eusMatch6.6.z
OR
redhatenterprise_linux_workstationMatch6.0
OR
redhatenterprise_linux_workstationMatch7.0
VendorProductVersionCPE
opensuseopensuse12.3cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
opensuseopensuse13.1cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
apachesubversion1.0.0cpe:2.3:a:apache:subversion:1.0.0:*:*:*:*:*:*:*
apachesubversion1.0.1cpe:2.3:a:apache:subversion:1.0.1:*:*:*:*:*:*:*
apachesubversion1.0.2cpe:2.3:a:apache:subversion:1.0.2:*:*:*:*:*:*:*
apachesubversion1.0.3cpe:2.3:a:apache:subversion:1.0.3:*:*:*:*:*:*:*
apachesubversion1.0.4cpe:2.3:a:apache:subversion:1.0.4:*:*:*:*:*:*:*
apachesubversion1.0.5cpe:2.3:a:apache:subversion:1.0.5:*:*:*:*:*:*:*
apachesubversion1.0.6cpe:2.3:a:apache:subversion:1.0.6:*:*:*:*:*:*:*
apachesubversion1.0.7cpe:2.3:a:apache:subversion:1.0.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 1031

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

8.6

Confidence

High

EPSS

0.002

Percentile

57.0%