CVE-2015-3187: Apache Subversion
Medium severity, CVSS 4.0. EPSS: 6.6% chance of exploitation in the next 30 days.
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.
Affected products
- Apache Subversion: up to and including 1.7.20; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; version 1.8.5 only; …
- Apple Xcode: up to and including 7.2.1
Published 2015-08-12. Last modified 2026-06-17.