diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index ab6e21fb655d..810b11bcf369 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,41 @@ Notes: --> + + subversion -- multiple vulnerabilities + + + subversion + 1.8.01.8.14 + 1.7.01.7.21 + + + + +

Subversion reports:

+
+

CVE-2015-3184:
+ Subversion's mod_authz_svn does not properly restrict anonymous access + in some mixed anonymous/authenticated environments when + using Apache httpd 2.4.

+

CVE-2015-3187:
+ Subversion servers, both httpd and svnserve, will reveal some + paths that should be hidden by path-based authz.

+
+ +
+ + CVE-2015-3184 + http://subversion.apache.org/security/CVE-2015-3184-advisory.txt + CVE-2015-3187 + http://subversion.apache.org/security/CVE-2015-3187-advisory.txt + + + 2015-07-27 + 2015-08-06 + +
+ elasticsearch -- directory traversal attack via snapshot API