VDB

DEBIAN-CVE-2007-2448

DEBIAN-CVE-2007-2448 PUBLISHED CVSS 7 HIGH

Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.

Risk Scores

CVSS v4.0
7
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:14subversion0, 0, 0
Debian:13subversion0, 0, 0
Debian:11subversion0, 0, 0
Debian:12subversion0, 0, 0

Timeline

  • Jun 14, 2007 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›