CVE-2013-6892

low
Published 2015-01-21 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debian7.0affected

Application impact

VendorProductVersionsFixed
websvnwebsvn2.3.3

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.