CVE-2021-28544 - CVE House
Back to Database
Status published Medium CVE-2021-28544

Apache Subversion SVN authz protected copyfrom paths regression

Vulnerability Description

Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-28544

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Apache Subversion would like to thank Evgeny Kotkov, visualsvn.com.

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Subversion
Vulnerable Versions:
1.10.0 to 1.14.1

Timeline

Official Publish: April 12th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)