CVE-2010-3315
subversion - authentication bypass
EPSS 4.2%
描述
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
如何修補 CVE-2010-3315
要修補 CVE-2010-3315,請將受影響套件升級到下列已修補版本。
- Debian/subversion—升級至 1.6.12dfsg-2 或更新版本
- Debian/subversion—升級至 1.5.1dfsg1-5 或更新版本
CVE-2010-3315 正在被利用嗎?
低 — EPSS 為 4.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1.6.12dfsg-2
- from 0, < 1.5.1dfsg1-5