{"api_version":"1","generated_at":"2026-07-23T19:56:02+00:00","cve":"CVE-2007-2448","urls":{"html":"https://cve.report/CVE-2007-2448","api":"https://cve.report/api/cve/CVE-2007-2448.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2448","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2448"},"summary":{"title":"CVE-2007-2448","description":"Subversion 1.4.3 and earlier does not properly implement the \"partial access\" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.","state":"PUBLISHED","assigner":"redhat","published_at":"2007-06-14 23:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:N/AC:H/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:N/A:N","baseScore":2.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://issues.rpath.com/browse/RPL-1896","name":"https://issues.rpath.com/browse/RPL-1896","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2007/2230","name":"http://www.vupen.com/english/advisories/2007/2230","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0264","name":"http://www.vupen.com/english/advisories/2011/0264","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36070","name":"http://osvdb.org/36070","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/USN-1053-1","name":"http://www.ubuntu.com/usn/USN-1053-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-1053-1: Subversion vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://subversion.tigris.org/security/CVE-2007-2448-advisory.txt","name":"http://subversion.tigris.org/security/CVE-2007-2448-advisory.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24463","name":"http://www.securityfocus.com/bid/24463","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Subversion Remote Revision Property Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1018237","name":"http://securitytracker.com/id?1018237","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"SecurityTracker.com Archives - Subversion Discloses Potentially Sensitive Revision Properties to Remote Authenticated Users in Certain Cases","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43139","name":"http://secunia.com/advisories/43139","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ubuntu update for subversion - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2448","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2448","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2448","vulnerable":"1","versionEndIncluding":"1.4.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"subversion","cpe5":"subversion","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2007-2448","organization":"Red Hat","lastmodified":"2007-06-26","contributor":"Mark J Cox","statementText":"Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-2448 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.","cve_year":"2007","cve_id":"2448","crc32":"3acd9a95"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:42:33.422Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://issues.rpath.com/browse/RPL-1896"},{"name":"36070","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36070"},{"name":"ADV-2011-0264","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0264"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://subversion.tigris.org/security/CVE-2007-2448-advisory.txt"},{"name":"ADV-2007-2230","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2230"},{"name":"USN-1053-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1053-1"},{"name":"1018237","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1018237"},{"name":"43139","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43139"},{"name":"24463","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24463"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Subversion 1.4.3 and earlier does not properly implement the \"partial access\" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-06-22T09:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://issues.rpath.com/browse/RPL-1896"},{"name":"36070","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36070"},{"name":"ADV-2011-0264","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0264"},{"tags":["x_refsource_CONFIRM"],"url":"http://subversion.tigris.org/security/CVE-2007-2448-advisory.txt"},{"name":"ADV-2007-2230","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2230"},{"name":"USN-1053-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1053-1"},{"name":"1018237","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1018237"},{"name":"43139","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43139"},{"name":"24463","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24463"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2007-2448","datePublished":"2007-06-14T23:00:00.000Z","dateReserved":"2007-05-02T00:00:00.000Z","dateUpdated":"2024-08-07T13:42:33.422Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-14 23:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:N/A:N","baseScore":2.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:subversion:subversion:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.3","matchCriteriaId":"9B1D817D-D7D7-44B9-A05F-F674539F9896"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2448","Ordinal":"1","Title":"CVE-2007-2448","CVE":"CVE-2007-2448","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2448","Ordinal":"1","NoteData":"Subversion 1.4.3 and earlier does not properly implement the \"partial access\" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.","Type":"Description","Title":"CVE-2007-2448"},{"CveYear":"2007","CveId":"2448","Ordinal":"2","NoteData":"2007-06-14","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2448","Ordinal":"3","NoteData":"2007-06-22","Type":"Other","Title":"Modified"}]}}}