CVE-2015-3184
Apache Subversion <1.7.21, <1.8.14 - Info Disclosure
Title source: llmDescription
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
References (10)
Scores
EPSS
0.1701
EPSS Percentile
94.9%
Classification
CWE
CWE-200
Status
draft
Affected Products (35)
apple/xcode
< 7.2.1
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
apache/subversion
... and 20 more
Timeline
Published
Aug 12, 2015
Tracked Since
Feb 18, 2026