CVE-2015-3187: Apache Subversion

Medium severity, CVSS 4.0. EPSS: 6.6% chance of exploitation in the next 30 days.

The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.

Affected products

  • Apache Subversion: up to and including 1.7.20; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; version 1.8.5 only; …
  • Apple Xcode: up to and including 7.2.1

Published 2015-08-12. Last modified 2026-06-17.