CVE-2009-0240: Low severity Tigris Websvn vulnerability
listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0240?
CVE-2009-0240 is rated as a moderate severity vulnerability due to the potential for remote authenticated users to access restricted project information.
How do I fix CVE-2009-0240?
To fix CVE-2009-0240, upgrade to the latest version of WebSVN that addresses this vulnerability.
Who is affected by CVE-2009-0240?
CVE-2009-0240 affects users of WebSVN versions 2.0 and possibly 1.7 beta when using an SVN authz file.
What type of attacks are possible with CVE-2009-0240?
With CVE-2009-0240, an attacker can exploit the vulnerability to read changelogs or diffs for projects that should be restricted.
Is user authentication required for CVE-2009-0240 to be exploited?
Yes, exploitation of CVE-2009-0240 requires remote authenticated access to the affected WebSVN application.