CVE-2011-1921

Apache Subversion <1.6.17 - Info Disclosure

Title source: llm

Description

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.

References (20)

Scores

EPSS 0.0404
EPSS Percentile 88.3%

Classification

CWE
CWE-264
Status draft

Affected Products (26)

apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
... and 11 more

Timeline

Published Jun 06, 2011
Tracked Since Feb 18, 2026