CVE Vulnerabilities

CVE-2015-0251

Insufficient Verification of Data Authenticity

Published: Apr 08, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
SubversionApache1.5.0 (including)1.5.0 (including)
SubversionApache1.5.1 (including)1.5.1 (including)
SubversionApache1.5.2 (including)1.5.2 (including)
SubversionApache1.5.3 (including)1.5.3 (including)
SubversionApache1.5.4 (including)1.5.4 (including)
SubversionApache1.5.5 (including)1.5.5 (including)
SubversionApache1.5.6 (including)1.5.6 (including)
SubversionApache1.5.7 (including)1.5.7 (including)
SubversionApache1.5.8 (including)1.5.8 (including)
SubversionApache1.6.0 (including)1.6.0 (including)
SubversionApache1.6.1 (including)1.6.1 (including)
SubversionApache1.6.2 (including)1.6.2 (including)
SubversionApache1.6.3 (including)1.6.3 (including)
SubversionApache1.6.4 (including)1.6.4 (including)
SubversionApache1.6.5 (including)1.6.5 (including)
SubversionApache1.6.6 (including)1.6.6 (including)
SubversionApache1.6.7 (including)1.6.7 (including)
SubversionApache1.6.8 (including)1.6.8 (including)
SubversionApache1.6.9 (including)1.6.9 (including)
SubversionApache1.6.10 (including)1.6.10 (including)
SubversionApache1.6.11 (including)1.6.11 (including)
SubversionApache1.6.12 (including)1.6.12 (including)
SubversionApache1.6.13 (including)1.6.13 (including)
SubversionApache1.6.14 (including)1.6.14 (including)
SubversionApache1.6.15 (including)1.6.15 (including)
SubversionApache1.6.16 (including)1.6.16 (including)
SubversionApache1.6.17 (including)1.6.17 (including)
SubversionApache1.6.18 (including)1.6.18 (including)
SubversionApache1.6.19 (including)1.6.19 (including)
SubversionApache1.6.20 (including)1.6.20 (including)
SubversionApache1.6.21 (including)1.6.21 (including)
SubversionApache1.6.23 (including)1.6.23 (including)
SubversionApache1.7.0 (including)1.7.0 (including)
SubversionApache1.7.1 (including)1.7.1 (including)
SubversionApache1.7.2 (including)1.7.2 (including)
SubversionApache1.7.3 (including)1.7.3 (including)
SubversionApache1.7.4 (including)1.7.4 (including)
SubversionApache1.7.5 (including)1.7.5 (including)
SubversionApache1.7.6 (including)1.7.6 (including)
SubversionApache1.7.7 (including)1.7.7 (including)
SubversionApache1.7.8 (including)1.7.8 (including)
SubversionApache1.7.9 (including)1.7.9 (including)
SubversionApache1.7.10 (including)1.7.10 (including)
SubversionApache1.7.11 (including)1.7.11 (including)
SubversionApache1.7.12 (including)1.7.12 (including)
SubversionApache1.7.13 (including)1.7.13 (including)
SubversionApache1.7.14 (including)1.7.14 (including)
SubversionApache1.7.15 (including)1.7.15 (including)
SubversionApache1.7.16 (including)1.7.16 (including)
SubversionApache1.7.17 (including)1.7.17 (including)
SubversionApache1.7.18 (including)1.7.18 (including)
SubversionApache1.7.19 (including)1.7.19 (including)
SubversionApache1.8.0 (including)1.8.0 (including)
SubversionApache1.8.1 (including)1.8.1 (including)
SubversionApache1.8.2 (including)1.8.2 (including)
SubversionApache1.8.3 (including)1.8.3 (including)
SubversionApache1.8.4 (including)1.8.4 (including)
SubversionApache1.8.5 (including)1.8.5 (including)
SubversionApache1.8.6 (including)1.8.6 (including)
SubversionApache1.8.7 (including)1.8.7 (including)
SubversionApache1.8.8 (including)1.8.8 (including)
SubversionApache1.8.9 (including)1.8.9 (including)
SubversionApache1.8.10 (including)1.8.10 (including)
SubversionApache1.8.11 (including)1.8.11 (including)
Red Hat Enterprise Linux 6RedHatsubversion-0:1.6.11-15.el6_7*
Red Hat Enterprise Linux 7RedHatsubversion-0:1.7.14-7.el7_1.1*
SubversionUbuntulucid*
SubversionUbuntuprecise*
SubversionUbuntutrusty*
SubversionUbuntuupstream*
SubversionUbuntuutopic*
SubversionUbuntuvivid*

References