Lucene search

K
cveRedhatCVE-2015-0251
HistoryApr 08, 2015 - 6:59 p.m.

CVE-2015-0251

2015-04-0818:59:02
CWE-345
redhat
web.nvd.nist.gov
81
cve-2015-0251
nvd
mod_dav_svn
subversion
spoofing
authenticated users
v1 http protocol

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

7.7

Confidence

High

EPSS

0.004

Percentile

74.9%

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.

Affected configurations

Nvd
Node
apachesubversionMatch1.5.0
OR
apachesubversionMatch1.5.1
OR
apachesubversionMatch1.5.2
OR
apachesubversionMatch1.5.3
OR
apachesubversionMatch1.5.4
OR
apachesubversionMatch1.5.5
OR
apachesubversionMatch1.5.6
OR
apachesubversionMatch1.5.7
OR
apachesubversionMatch1.5.8
OR
apachesubversionMatch1.6.0
OR
apachesubversionMatch1.6.1
OR
apachesubversionMatch1.6.2
OR
apachesubversionMatch1.6.3
OR
apachesubversionMatch1.6.4
OR
apachesubversionMatch1.6.5
OR
apachesubversionMatch1.6.6
OR
apachesubversionMatch1.6.7
OR
apachesubversionMatch1.6.8
OR
apachesubversionMatch1.6.9
OR
apachesubversionMatch1.6.10
OR
apachesubversionMatch1.6.11
OR
apachesubversionMatch1.6.12
OR
apachesubversionMatch1.6.13
OR
apachesubversionMatch1.6.14
OR
apachesubversionMatch1.6.15
OR
apachesubversionMatch1.6.16
OR
apachesubversionMatch1.6.17
OR
apachesubversionMatch1.6.18
OR
apachesubversionMatch1.6.19
OR
apachesubversionMatch1.6.20
OR
apachesubversionMatch1.6.21
OR
apachesubversionMatch1.6.23
OR
apachesubversionMatch1.7.0
OR
apachesubversionMatch1.7.1
OR
apachesubversionMatch1.7.2
OR
apachesubversionMatch1.7.3
OR
apachesubversionMatch1.7.4
OR
apachesubversionMatch1.7.5
OR
apachesubversionMatch1.7.6
OR
apachesubversionMatch1.7.7
OR
apachesubversionMatch1.7.8
OR
apachesubversionMatch1.7.9
OR
apachesubversionMatch1.7.10
OR
apachesubversionMatch1.7.11
OR
apachesubversionMatch1.7.12
OR
apachesubversionMatch1.7.13
OR
apachesubversionMatch1.7.14
OR
apachesubversionMatch1.7.15
OR
apachesubversionMatch1.7.16
OR
apachesubversionMatch1.7.17
OR
apachesubversionMatch1.7.18
OR
apachesubversionMatch1.7.19
OR
apachesubversionMatch1.8.0
OR
apachesubversionMatch1.8.1
OR
apachesubversionMatch1.8.2
OR
apachesubversionMatch1.8.3
OR
apachesubversionMatch1.8.4
OR
apachesubversionMatch1.8.5
OR
apachesubversionMatch1.8.6
OR
apachesubversionMatch1.8.7
OR
apachesubversionMatch1.8.8
OR
apachesubversionMatch1.8.9
OR
apachesubversionMatch1.8.10
OR
apachesubversionMatch1.8.11
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_hpc_nodeMatch6.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_server_eusMatch6.7.z
OR
redhatenterprise_linux_workstationMatch6.0
Node
oraclesolarisMatch11.3
Node
applexcodeMatch7.0
VendorProductVersionCPE
apachesubversion1.5.0cpe:2.3:a:apache:subversion:1.5.0:*:*:*:*:*:*:*
apachesubversion1.5.1cpe:2.3:a:apache:subversion:1.5.1:*:*:*:*:*:*:*
apachesubversion1.5.2cpe:2.3:a:apache:subversion:1.5.2:*:*:*:*:*:*:*
apachesubversion1.5.3cpe:2.3:a:apache:subversion:1.5.3:*:*:*:*:*:*:*
apachesubversion1.5.4cpe:2.3:a:apache:subversion:1.5.4:*:*:*:*:*:*:*
apachesubversion1.5.5cpe:2.3:a:apache:subversion:1.5.5:*:*:*:*:*:*:*
apachesubversion1.5.6cpe:2.3:a:apache:subversion:1.5.6:*:*:*:*:*:*:*
apachesubversion1.5.7cpe:2.3:a:apache:subversion:1.5.7:*:*:*:*:*:*:*
apachesubversion1.5.8cpe:2.3:a:apache:subversion:1.5.8:*:*:*:*:*:*:*
apachesubversion1.6.0cpe:2.3:a:apache:subversion:1.6.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 731

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

7.7

Confidence

High

EPSS

0.004

Percentile

74.9%