CVE-2007-2448
Summary
| CVE | CVE-2007-2448 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-06-14 23:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:N/AC:H/Au:S/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:H/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Subversion | Subversion | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| issues.rpath.com/browse/RPL-1896 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| osvdb.org/36070 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| USN-1053-1: Subversion vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| subversion.tigris.org/security/CVE-2007-2448-advisory.txt | af854a3a-2127-422b-91ae-364da2661108 | subversion.tigris.org | |
| Subversion Remote Revision Property Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| SecurityTracker.com Archives - Subversion Discloses Potentially Sensitive Revision Properties to Remote Authenticated Users in Certain Cases | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| Ubuntu update for subversion - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-06-26 | Mark J Cox | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-2448 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. |
There are currently no legacy QID mappings associated with this CVE.