Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24697
HistoryApr 10, 2020 - 1:01 a.m.

Denial Of Service (DoS)

2020-04-1001:01:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.007 Low

EPSS

Percentile

80.6%

subversion is vulnerable to denial of service. An infinite loop flaw was found in the way the mod_dav_svn module processed certain data sets. If the SVNPathAuthz directive was set to β€œshort_circuit”, and path-based access control for files and directories was enabled, a malicious, remote user could use this flaw to cause the httpd process serving the request to consume an excessive amount of system memory.

References