CVE-2004-1438: Low severity Subversion Subversion vulnerability
Published Dec 31, 2004
·Updated
The modauthzsvn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
Affected Software
6 affected components
Subversion Subversion=1.0.4
Subversion Subversion=1.0.5
Subversion Subversion=1.0.2
Subversion Subversion=1.0.1
Subversion Subversion=1.0
Subversion Subversion=1.0.3
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1438?
CVE-2004-1438 is considered a moderate severity vulnerability that allows unauthorized data access.
2
How do I fix CVE-2004-1438?
To fix CVE-2004-1438, upgrade Subversion to version 1.0.6 or later.
3
Who is affected by CVE-2004-1438?
CVE-2004-1438 affects installations of Apache's mod_authz_svn module for Subversion version 1.0.4 and earlier.
4
What type of attack does CVE-2004-1438 allow?
CVE-2004-1438 allows remote authenticated users with write access to compromise repository confidentiality.
5
Is CVE-2004-1438 still an issue in newer versions of Subversion?
No, CVE-2004-1438 has been addressed and is not an issue in versions later than 1.0.6.