Description
listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1725-1 | New websvn packages fix information leak |
EUVD |
EUVD-2009-0248 | listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T04:24:18.369Z
Reserved: 2009-01-20T00:00:00.000Z
Link: CVE-2009-0240
No data.
Status : Modified
Published: 2009-01-21T02:30:00.327
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-0240
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD