Back to Database
Status published
Medium
CVE-2015-0251
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0...
Vulnerability Description
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-0251
Credits & Attribution
No credits recorded in the NVD database.
References
- http://rhn.redhat.com/errata/RHSA-2015-1742.html
- http://www.debian.org/security/2015/dsa-3231
- http://rhn.redhat.com/errata/RHSA-2015-1633.html
- http://seclists.org/fulldisclosure/2015/Jun/32
- http://www.securityfocus.com/bid/74259
- http://www.securitytracker.com/id/1033214
- https://support.apple.com/HT205217
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:192
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html
- http://subversion.apache.org/security/CVE-2015-0251-advisory.txt
- http://www.ubuntu.com/usn/USN-2721-1
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00008.html
- https://security.gentoo.org/glsa/201610-05
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
More from apache
View All →CVE-2025-58712
Amq: privilege escalation via excessive /etc/passwd permissions
Medium
6.4
CVE-2021-25958
Generation of Error Message Containing Sensitive Information in Apache OFBiz
Medium
6.5
CVE-2021-24117
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability...
Medium
4.9
CVE-2020-5499
Baidu Rust SGX SDK through 1.0.8 has an enclave ID...
Critical
9.8
CVE-2018-14889
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3...
High
7.8
Affected Vendor
apache
View all reports →Affected Software
subversion, opensuse, enterprise linux desktop, enterprise linux hpc node, enterprise linux server, enterprise linux server eus, enterprise linux workstation, solaris, xcode
Vulnerable Versions:
1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5, 1.5.6, 1.5.7, 1.5.8, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.6.5, 1.6.6, 1.6.7, 1.6.8, 1.6.9, 1.6.10, 1.6.11, 1.6.12, 1.6.13, 1.6.14, 1.6.15, 1.6.16, 1.6.17, 1.6.18, 1.6.19, 1.6.20, 1.6.21, 1.6.23, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.7.5, 1.7.6, 1.7.7, 1.7.8, 1.7.9, 1.7.10, 1.7.11, 1.7.12, 1.7.13, 1.7.14, 1.7.15, 1.7.16, 1.7.17, 1.7.18, 1.7.19, 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.8.6, 1.8.7, 1.8.8, 1.8.9, 1.8.10, 1.8.11, 13.1, 13.2, 6.0, 6.7.z, 11.3, 7.0
Timeline
Official Publish:
April 8th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.