Back to Database
Status published
High
CVE-2013-2088
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with...
Vulnerability Description
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-2088
Credits & Attribution
No credits recorded in the NVD database.
References
- http://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3E
- http://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3E
- https://subversion.apache.org/security/CVE-2013-2088-advisory.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18772
- https://www.exploit-db.com/exploits/40507/
- http://lists.opensuse.org/opensuse-updates/2013-07/msg00015.html
More from apache
View All →CVE-2025-58712
Amq: privilege escalation via excessive /etc/passwd permissions
Medium
6.4
CVE-2021-25958
Generation of Error Message Containing Sensitive Information in Apache OFBiz
Medium
6.5
CVE-2021-24117
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability...
Medium
4.9
CVE-2020-5499
Baidu Rust SGX SDK through 1.0.8 has an enclave ID...
Critical
9.8
CVE-2018-14889
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3...
High
7.8
Affected Vendor
apache
View all reports →Affected Software
subversion, opensuse
Vulnerable Versions:
0, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.6.5, 1.6.6, 1.6.7, 1.6.8, 1.6.9, 1.6.10, 1.6.11, 1.6.12, 1.6.13, 1.6.14, 1.6.15, 1.6.16, 1.6.17, 1.6.18, 1.6.19, 1.6.20, 11.4
Timeline
Official Publish:
July 31st, 2013
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.