V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2014-3528
DEB
Low

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store c…

CVSS
2.6
Low
EPSS
0.03
p87
Published
2014-01-01
Updated
2014-01-01
Description

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

Tags · CWE
Crypto
CWE-255
CWE-327
CAPEC-20
CAPEC-97
CAPEC-459
CAPEC-473
CAPEC-475
CAPEC-608
CAPEC-614
Affected products
Enterprise_linux_desktopEnterprise_linux_hpc_nodeEnterprise_linux_serverEnterprise_linux_server_eusEnterprise_linux_workstation
CVSS vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.034 · p87
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-473 · CWE-327
└ via CAPEC-473 · CWE-327
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
subversionTracked
subversionTracked
subversionTracked
subversionTracked
subversionTracked
subversionTracked
enterprise_linux_desktop*Tracked
enterprise_linux_hpc_node*Tracked
enterprise_linux_server*Tracked
enterprise_linux_server_eus*Tracked
enterprise_linux_workstation*Tracked
opensuse*Tracked
subversion*Tracked
ubuntu_linux*Tracked
xcode*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities