CVE-2015-0251

Public on 2015-04-08
Modified on 2015-08-24
Description
It was found that the mod_dav_svn module did not properly validate the svn:author property of certain requests. An attacker able to create new revisions could use this flaw to spoof the svn:author property.
Severity
Low severity
Low
CVSS v3 Base Score
3.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 mod_dav_svn 2015-08-24 ALAS-2015-587 Fixed
Amazon Linux 1 subversion 2015-08-24 ALAS-2015-587 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 3.5 AV:N/AC:M/Au:S/C:N/I:P/A:N
NVD CVSSv2 4.0 AV:N/AC:L/Au:S/C:N/I:P/A:N