CVE-2015-3184
Summary
| CVE | CVE-2015-3184 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-12 14:59:10 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | 2.4.1 | All | All | All |
| Application | Apache | Http Server | 2.4.10 | All | All | All |
| Application | Apache | Http Server | 2.4.12 | All | All | All |
| Application | Apache | Http Server | 2.4.14 | All | All | All |
| Application | Apache | Http Server | 2.4.16 | All | All | All |
| Application | Apache | Http Server | 2.4.2 | All | All | All |
| Application | Apache | Http Server | 2.4.3 | All | All | All |
| Application | Apache | Http Server | 2.4.4 | All | All | All |
| Application | Apache | Http Server | 2.4.6 | All | All | All |
| Application | Apache | Http Server | 2.4.7 | All | All | All |
| Application | Apache | Http Server | 2.4.9 | All | All | All |
| Application | Apache | Subversion | 1.7.0 | All | All | All |
| Application | Apache | Subversion | 1.7.1 | All | All | All |
| Application | Apache | Subversion | 1.7.10 | All | All | All |
| Application | Apache | Subversion | 1.7.11 | All | All | All |
| Application | Apache | Subversion | 1.7.12 | All | All | All |
| Application | Apache | Subversion | 1.7.13 | All | All | All |
| Application | Apache | Subversion | 1.7.14 | All | All | All |
| Application | Apache | Subversion | 1.7.15 | All | All | All |
| Application | Apache | Subversion | 1.7.16 | All | All | All |
| Application | Apache | Subversion | 1.7.17 | All | All | All |
| Application | Apache | Subversion | 1.7.18 | All | All | All |
| Application | Apache | Subversion | 1.7.19 | All | All | All |
| Application | Apache | Subversion | 1.7.2 | All | All | All |
| Application | Apache | Subversion | 1.7.20 | All | All | All |
| Application | Apache | Subversion | 1.7.3 | All | All | All |
| Application | Apache | Subversion | 1.7.4 | All | All | All |
| Application | Apache | Subversion | 1.7.5 | All | All | All |
| Application | Apache | Subversion | 1.7.6 | All | All | All |
| Application | Apache | Subversion | 1.7.7 | All | All | All |
| Application | Apache | Subversion | 1.7.8 | All | All | All |
| Application | Apache | Subversion | 1.7.9 | All | All | All |
| Application | Apache | Subversion | 1.8.0 | All | All | All |
| Application | Apache | Subversion | 1.8.1 | All | All | All |
| Application | Apache | Subversion | 1.8.10 | All | All | All |
| Application | Apache | Subversion | 1.8.11 | All | All | All |
| Application | Apache | Subversion | 1.8.13 | All | All | All |
| Application | Apache | Subversion | 1.8.2 | All | All | All |
| Application | Apache | Subversion | 1.8.3 | All | All | All |
| Application | Apache | Subversion | 1.8.4 | All | All | All |
| Application | Apache | Subversion | 1.8.5 | All | All | All |
| Application | Apache | Subversion | 1.8.6 | All | All | All |
| Application | Apache | Subversion | 1.8.7 | All | All | All |
| Application | Apache | Subversion | 1.8.8 | All | All | All |
| Application | Apache | Subversion | 1.8.9 | All | All | All |
| Application | Apple | Xcode | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-2721-1: Subversion vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Debian -- Security Information -- DSA-3331-1 subversion | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| repos - Revision 1: /A/D | af854a3a-2127-422b-91ae-364da2661108 | subversion.apache.org | Vendor Advisory |
| About the security content of Xcode 7.3 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| openSUSE-SU-2015:1401-1: moderate: Security update for subversion | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Apache Subversion Bugs Let Remote Users Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Subversion, Serf: Multiple Vulnerabilities (GLSA 201610-05) — Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| APPLE-SA-2016-03-21-4 Xcode 7.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Apache Subversion CVE-2015-3184 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.