CVE-2015-0251: Medium severity subversion vulnerability
The moddavsvn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0251?
CVE-2015-0251 has a medium severity rating due to its ability to allow remote authenticated users to spoof the svn:author property.
How do I fix CVE-2015-0251?
To fix CVE-2015-0251, upgrade to Subversion version 1.8.12 or later, or apply patches as recommended by your vendor.
What versions of Subversion are affected by CVE-2015-0251?
CVE-2015-0251 affects Subversion versions 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11.
Can CVE-2015-0251 lead to unauthorized changes?
Yes, CVE-2015-0251 can lead to unauthorized changes by allowing attackers to spoof the author of commits.
Who is at risk of CVE-2015-0251?
Remote authenticated users of Subversion who are using affected versions are at risk of the CVE-2015-0251 vulnerability.