CVE-2013-4505
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
07/12/2013
Last modified:
11/04/2025
Description
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
Impact
Base Score 2.0
2.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:mod_dontdothat:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.4.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.4.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.4.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.4.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.4.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.4.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.5.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.5.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.5.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.5.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.5.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:subversion:1.5.6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00029.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00048.html
- http://osvdb.org/100364
- http://secunia.com/advisories/55855
- http://subversion.apache.org/security/CVE-2013-4505-advisory.txt
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00029.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00048.html
- http://osvdb.org/100364
- http://secunia.com/advisories/55855
- http://subversion.apache.org/security/CVE-2013-4505-advisory.txt