First published: Thu Jun 14 2007(Updated: )
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Subversion | <=1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2448 is considered a medium severity vulnerability due to its potential exposure of sensitive revision properties.
To fix CVE-2007-2448, upgrade to Subversion version 1.4.4 or later to ensure proper implementation of access controls.
CVE-2007-2448 affects Subversion versions 1.4.3 and earlier.
Attackers with authenticated access can exploit CVE-2007-2448 to retrieve sensitive information from revision properties.
CVE-2007-2448 is a remote vulnerability that allows authenticated users to exploit the access control failure.