Skip to content

CVE-2014-3528

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0338 (3.4%)
Percentile: 87.4%
EPSS: 2026-05-06

Affects

opensuse:opensuseapache:subversioncanonical:ubuntu_linuxapple:xcoderedhat:enterprise_linux_desktopredhat:enterprise_linux_hpc_noderedhat:enterprise_linux_serverredhat:enterprise_linux_server_eusredhat:enterprise_linux_workstation

Technical description

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

Published: 8/19/2014, 6:55:02 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam