listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/33945 | third party advisory |
http://secunia.com/advisories/34191 | third party advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191 | |
http://www.gentoo.org/security/en/glsa/glsa-200903-20.xml | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48171 | vdb entry |
http://www.openwall.com/lists/oss-security/2009/01/18/2 | mailing list |
http://secunia.com/advisories/32338 | third party advisory vendor advisory |
http://www.debian.org/security/2009/dsa-1725 | vendor advisory |