CVE-2007-2448

medium

Description

Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.

References

https://issues.rpath.com/browse/RPL-1896

http://www.vupen.com/english/advisories/2011/0264

http://www.vupen.com/english/advisories/2007/2230

http://www.ubuntu.com/usn/USN-1053-1

http://www.securityfocus.com/bid/24463

http://subversion.tigris.org/security/CVE-2007-2448-advisory.txt

http://securitytracker.com/id?1018237

http://secunia.com/advisories/43139

http://osvdb.org/36070

Details

Source: Mitre, NVD

Published: 2007-06-14

Updated: 2012-11-06

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium