{"id":"CVE-2011-1921","details":"The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.","modified":"2026-04-10T03:41:47.335519Z","published":"2011-06-06T19:55:02Z","related":["openSUSE-SU-2024:10538-1"],"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/44633"},{"type":"ADVISORY","url":"http://secunia.com/advisories/44681"},{"type":"ADVISORY","url":"http://secunia.com/advisories/44849"},{"type":"ADVISORY","url":"http://secunia.com/advisories/44888"},{"type":"ADVISORY","url":"http://secunia.com/advisories/45162"},{"type":"ADVISORY","url":"http://subversion.apache.org/security/CVE-2011-1921-advisory.txt"},{"type":"ADVISORY","url":"http://www.debian.org/security/2011/dsa-2251"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:106"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1144-1"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=709114"},{"type":"WEB","url":"http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.html"},{"type":"WEB","url":"http://support.apple.com/kb/HT5130"},{"type":"WEB","url":"http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGES"},{"type":"WEB","url":"http://www.redhat.com/support/errata/RHSA-2011-0862.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/48091"},{"type":"WEB","url":"http://www.securitytracker.com/id?1025619"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/67804"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18999"}],"schema_version":"1.7.5"}