CVE-2015-3184
medium · 5mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
5
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2015-08-12
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | xcode | <= 7.2.1 |
| apache | subversion | 1.7.0 |
| apache | subversion | 1.7.1 |
| apache | subversion | 1.7.2 |
| apache | subversion | 1.7.3 |
| apache | subversion | 1.7.4 |
| apache | subversion | 1.7.5 |
| apache | subversion | 1.7.6 |
| apache | subversion | 1.7.7 |
| apache | subversion | 1.7.8 |
| apache | subversion | 1.7.9 |
| apache | subversion | 1.7.10 |
| apache | subversion | 1.7.11 |
| apache | subversion | 1.7.12 |
| apache | subversion | 1.7.13 |
| apache | subversion | 1.7.14 |
| apache | subversion | 1.7.15 |
| apache | subversion | 1.7.16 |
| apache | subversion | 1.7.17 |
| apache | subversion | 1.7.18 |
| apache | subversion | 1.7.19 |
| apache | subversion | 1.7.20 |
| apache | subversion | 1.8.0 |
| apache | subversion | 1.8.1 |
| apache | subversion | 1.8.2 |
| apache | subversion | 1.8.3 |
| apache | subversion | 1.8.4 |
| apache | subversion | 1.8.5 |
| apache | subversion | 1.8.6 |
| apache | subversion | 1.8.7 |
| apache | subversion | 1.8.8 |
| apache | subversion | 1.8.9 |
| apache | subversion | 1.8.10 |
| apache | subversion | 1.8.11 |
| apache | subversion | 1.8.13 |
| apache | http_server | 2.4.1 |
| apache | http_server | 2.4.2 |
| apache | http_server | 2.4.3 |
| apache | http_server | 2.4.4 |
| apache | http_server | 2.4.6 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2015-08/msg00022.html
- http://rhn.redhat.com/errata/RHSA-2015-1742.html
- http://subversion.apache.org/security/CVE-2015-3184-advisory.txt
- http://www.debian.org/security/2015/dsa-3331
- http://www.securityfocus.com/bid/76274
- http://www.securitytracker.com/id/1033215
- http://www.ubuntu.com/usn/USN-2721-1
- https://security.gentoo.org/glsa/201610-05
- https://support.apple.com/HT206172
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2015-08/msg00022.html
- http://rhn.redhat.com/errata/RHSA-2015-1742.html
- http://subversion.apache.org/security/CVE-2015-3184-advisory.txt
- http://www.debian.org/security/2015/dsa-3331
- http://www.securityfocus.com/bid/76274
- http://www.securitytracker.com/id/1033215
- http://www.ubuntu.com/usn/USN-2721-1
- https://security.gentoo.org/glsa/201610-05
- https://support.apple.com/HT206172
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-3184