CVE-2014-3522: Apache Subversion
Medium severity, CVSS 4.0. EPSS: 5.6% chance of exploitation in the next 30 days.
The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Affected products
- Apache Subversion: version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.4.4 only; version 1.4.5 only; …
- Apple Xcode: version 6.1.1 only
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
- Opensuse Opensuse: version 12.3 only; version 13.1 only
Published 2014-08-19. Last modified 2026-06-17.