CVE-2021-28544

Priority
Description
Apache Subversion SVN authz protected copyfrom paths regression Subversion
servers reveal 'copyfrom' paths that should be hidden according to
configured path-based authorization (authz) rules. When a node has been
copied from a protected location, users with access to the copy can see the
'copyfrom' path of the original. This also reveals the fact that the node
was copied. Only the 'copyfrom' path is revealed; not its contents. Both
httpd and svnserve servers are vulnerable.
Ubuntu-Description
Evgeny Kotkov discovered that subversion servers did not properly
follow path-based authorization rules in certain cases. An attacker
could potentially use this issue to retrieve information about
private paths.
Notes
Package
Upstream:released (1.14.2 and 1.10.8)
Ubuntu 18.04 LTS:not-affected (1.9.7-4ubuntu1)
Ubuntu 20.04 LTS:released (1.13.0-3ubuntu0.1)
Ubuntu 21.10:released (1.14.1-3ubuntu0.1)
Ubuntu 16.04 ESM:not-affected (1.9.3-2ubuntu1.3+esm1)
Ubuntu 22.04 LTS:released (1.14.1-3ubuntu0.22.04.1)
Patches:
More Information

Updated: 2022-06-10 14:02:40 UTC (commit 22cd97abab61e5eccab4070a258ab5d6a94b972b)