CVE-2014-3528: Apache Subversion
Medium severity, CVSS 4.0. EPSS: 7.4% chance of exploitation in the next 30 days.
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
Affected products
- Apache Subversion: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; …
- Apple Xcode: version 6.1.1 only
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
- Opensuse Opensuse: version 12.3 only; version 13.1 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Hpc Node: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Eus: version 6.6.z only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
Published 2014-08-19. Last modified 2026-06-17.