mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2015-1742.html | vendor advisory |
https://support.apple.com/HT206172 | vendor advisory |
http://www.debian.org/security/2015/dsa-3331 | vendor advisory |
http://lists.opensuse.org/opensuse-updates/2015-08/msg00022.html | vendor advisory |
http://www.securityfocus.com/bid/76274 | vdb entry |
http://www.ubuntu.com/usn/USN-2721-1 | vendor advisory |
http://www.securitytracker.com/id/1033215 | vdb entry |
http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.html | vendor advisory |
https://security.gentoo.org/glsa/201610-05 | vendor advisory |
http://subversion.apache.org/security/CVE-2015-3184-advisory.txt | vendor advisory |