CVE-2016-2167

medium Apache
CVSS v3 Base Score
6.8
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
1.0%
Exploitation probability in 30 days
Top 23% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
High
Availability
None
Published: May 5, 2016 (3661 days ago)
Last Modified: May 6, 2026
Vendor: Apache
Source: NVD

Description

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.

CWE

CWE-284

Affected Products

apache subversion

References