Vulnerability record · CVE-2020-17525 · published 17 March 2021
CVE-2020-17525: Apache subversion null pointer dereference vulnerability
Apache · Subversion
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
Description
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.debian.org/debian-lts-announce/2021/05/msg00000.html | Mailing ListThird Party Advisory |
| https://subversion.apache.org/security/CVE-2020-17525-advisory.txt | ExploitPatchVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2021/05/msg00000.html | Mailing ListThird Party Advisory |
| https://subversion.apache.org/security/CVE-2020-17525-advisory.txt | ExploitPatchVendor Advisory |
Track CVE-2020-17525 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17525), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.