Loading
Generated remediation guidance and an executive summary. No account required.
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.
Use Subversion vendor hub and Subversion product page to widen CVE-2004-0749 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2004-0413, CVE-2009-2411 and CVE-2004-0397 for nearby disclosures in the same product family.