CVE-2021-28544

MEDIUM

Apache Subversion 1.10.0-1.14.0 - Unauthorized Exposure of Protected Copyfrom Paths

Title source: llm
STIX 2.1

Description

Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.

References (6)

Core 6
Core References
Exploit, Patch, Vendor Advisory x_refsource_misc
https://subversion.apache.org/security/CVE-2021-28544-advisory.txt
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2022/dsa-5119
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT213345
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/Jul/18

Scores

CVSS v3 4.3
EPSS 0.0036
EPSS Percentile 58.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (6)
apache/subversion 1.10.0 - 1.14.1
apple/macos 12.0 - 12.5
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 35
fedoraproject/fedora 36
Published Apr 12, 2022
Tracked Since Feb 18, 2026