CVE-2016-2167: Medium severity subversion vulnerability
The canonicalizeusername function in svnserve/cyrusauth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2167?
CVE-2016-2167 has a severity rating that indicates a moderate impact on security due to authentication bypass vulnerabilities.
How do I fix CVE-2016-2167?
To fix CVE-2016-2167, upgrade Apache Subversion to version 1.8.16 or later, or 1.9.4 or later.
What systems are affected by CVE-2016-2167?
CVE-2016-2167 affects Apache Subversion versions prior to 1.8.16 and 1.9.x before 1.9.4 when using Cyrus SASL authentication.
What type of vulnerability is CVE-2016-2167?
CVE-2016-2167 is an authentication bypass vulnerability affecting Apache Subversion.
Can CVE-2016-2167 be exploited remotely?
Yes, CVE-2016-2167 allows remote attackers to authenticate and bypass access restrictions.