CVE-2010-3315: Medium severity subversion vulnerability
authz.c in the moddavsvn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz shortcircuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3315?
CVE-2010-3315 is classified as a medium severity vulnerability.
How do I fix CVE-2010-3315?
To address CVE-2010-3315, upgrade to Subversion versions 1.5.8 or 1.6.13 and later.
Who is affected by CVE-2010-3315?
CVE-2010-3315 affects users of Apache Subversion versions 1.5.x before 1.5.8 and 1.6.x before 1.6.13.
What type of vulnerability is CVE-2010-3315?
CVE-2010-3315 is a security vulnerability that allows remote authenticated users to bypass authorization measures.
Can I safely use Apache Subversion versions 1.5.8 or 1.6.13 to avoid CVE-2010-3315?
Yes, upgrading to these versions or newer will mitigate the vulnerabilities associated with CVE-2010-3315.