CVE-2020-17525: Remote unauthenticated denial-of-service in Subversion mod_authz_svn
Subversion's modauthzsvn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in moddavsvn+modauthzsvn servers 1.14.1 and moddavsvn+modauthzsvn servers 1.10.7
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-17525.
What is the severity of CVE-2020-17525?
The severity of CVE-2020-17525 is high with a CVSS score of 7.5.
How does CVE-2020-17525 affect Apache Subversion?
CVE-2020-17525 affects Apache Subversion versions 1.9.0 to 1.10.7 and versions 1.11.0 to 1.14.1.
What is the impact of CVE-2020-17525?
The impact of CVE-2020-17525 is that Subversion's mod_authz_svn module may crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL, leading to disruption for users of the service.
How can I fix CVE-2020-17525?
To fix CVE-2020-17525, users should upgrade to a version of Apache Subversion that is not affected by this vulnerability.