The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade subversion | Jul 30, 2024 | Aug 19, 2014 |
| Freebsd | — | Upgrade subversion17Upgrade subversionUpgrade subversion16 | Dec 10, 2025 | Aug 11, 2014 |
| Gentoo Linux | — | Upgrade dev-vcs/subversion.Upgrade net-libs/serf. | Oct 30, 2017 | Aug 19, 2014 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3 | May 29, 2017 | Aug 19, 2014 |
| Suse | — | Upgrade subversionUpgrade subversion-pythonUpgrade subversion-bash-completionUpgrade libsvn_auth_kwallet-1-0Upgrade subversion-develUpgrade subversion-toolsUpgrade subversion-perlUpgrade subversion-serverUpgrade libsvn_auth_gnome_keyring-1-0 | Dec 18, 2015 | Aug 19, 2014 |
| Ubuntu | — | Upgrade libsvn1Upgrade libapache2-svnUpgrade subversion | Nov 8, 2024 | Aug 19, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub