Remote unauthenticated denial-of-service in Subversion mod_authz_svn
Vulnerability Description
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-17525
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Thomas Åkesson (simonsoft.se)
References
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →