CVE-2020-17525: Apache Subversion

High severity, CVSS 7.5. EPSS: 40.1% chance of exploitation in the next 30 days.

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7

Affected products

  • Apache Subversion: from 1.9.0, before 1.10.7 (fixed in 1.10.7); from 1.11.0, before 1.14.1 (fixed in 1.14.1)
  • Debian Debian Linux: version 9.0 only

Published 2021-03-17. Last modified 2026-06-17.