WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/62233 | third party advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775682 | issue tracking third party advisory |
http://www.debian.org/security/2015/dsa-3137 | third party advisory vendor advisory |