Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24698
HistoryApr 10, 2020 - 1:01 a.m.

Information Disclosure

2020-04-1001:01:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.002 Low

EPSS

Percentile

54.5%

subversion is vulnerable to information disclosure. An information disclosure flaw was found in the way the mod_dav_svn module processed certain URLs when path-based access control for files and directories was enabled. A malicious, remote user could possibly use this flaw to access certain files in a repository that would otherwise not be accessible to them. Note: This vulnerability cannot be triggered if the SVNPathAuthz directive is set to β€œshort_circuit”.

References