« Volver al listado

CVE-2019-0203

Estado: ModificadaAlta (7.5)—

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-0203",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Apache Subversion",
          "versions": [
            {
              "status": "affected",
              "version": "Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-09-26T16:15:10.440",
  "references": [
    {
      "url": "http://subversion.apache.org/security/CVE-2019-0203-advisory.txt",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://subversion.apache.org/security/CVE-2019-0203-advisory.txt",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        },
        {
          "lang": "en",
          "value": "CWE-755"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server."
    },
    {
      "lang": "es",
      "value": "En Apache Subversion versiones hasta 1.9.10, 1.10.4, 1.12.0 incluyéndolas, el proceso del servidor svnserve de Subversion puede cerrarse cuando un cliente envía determinadas secuencias de comandos de protocolo. Esto puede conllevar a interrupciones para los usuarios del servidor."
    }
  ],
  "lastModified": "2026-06-17T02:07:57.660",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50DD0181-B9AA-42E5-813E-8912532052BB",
              "versionEndIncluding": "1.9.10"
            },
            {
              "criteria": "cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "198D8E5E-4D92-43C4-8C30-C940255B4FB0",
              "versionEndIncluding": "1.10.4",
              "versionStartIncluding": "1.10.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A45E5978-D958-44EB-8434-63078915B03C",
              "versionEndIncluding": "1.11.1",
              "versionStartIncluding": "1.11.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:subversion:1.12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C60BCD44-BA16-4A6F-9B4D-2BA89601C76F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}