HIGH

CVE-2020-17525

CVSS v3

7.5

HIGH

EPSS Score

11.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7

Technical details

Published
3/17/2021

Frequently asked questions

What is CVE-2020-17525?

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7

Is CVE-2020-17525 actively exploited?

Active exploitation of CVE-2020-17525 has not been confirmed. The EPSS score is 11.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-17525?

CVE-2020-17525 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2020-17525 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.