The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade subversion | Aug 30, 2017 | Feb 14, 2014 |
| Debian | — | Upgrade subversion | Jul 30, 2024 | Dec 7, 2013 |
| Freebsd | — | Upgrade subversion | Dec 10, 2025 | Nov 25, 2013 |
| Suse | — | Upgrade sle-sdk-releaseUpgrade subversion-pythonUpgrade subversion-serverUpgrade libsvn_auth_kwallet-1-0Upgrade subversion-toolsUpgrade subversionUpgrade libsvn_auth_gnome_keyring-1-0Upgrade subversion-develUpgrade subversion-perlUpgrade subversion-bash-completionUpgrade subversion-ruby | Dec 12, 2013 | Dec 7, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub