CVE-2011-1921

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.

Published: 2011-06-06 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2011-1921 is rated Moderate Risk (51.5/100): CVSS Medium severity, with high exploitation likelihood (EPSS 5.99%, 92th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +1.96% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2011-1921

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 4.04% 5.99% +1.96%
2 2025-12-28 5.14% 4.04% -1.10%
3 2025-12-27 5.14%

Full EPSS history (16 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2011-1921

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2011-1921

OS Trackers for CVE-2011-1921

vendor priority summary link
debian not yet assigned CVE-2011-1921 not yet assigned priority: Debian including 1 source packages (subversion), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2011-1921
gentoo low CVE-2011-1921: 1 GLSA(s) (201309-11), 1 atom(s) (dev-vcs/subversion); latest impact low. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2011-1921
redhat low https://access.redhat.com/security/cve/CVE-2011-1921
ubuntu medium CVE-2011-1921 medium priority: Ubuntu including 1 source packages (subversion), 5 status rows across 5 suites (hardy, lucid, maverick, natty, upstream): released 4, ignored 1. https://ubuntu.com/security/CVE-2011-1921

Affected software / configurations for CVE-2011-1921

Vendor Product Version Raw CPE
apache subversion 1.5.0 cpe:2.3:a:apache:subversion:1.5.0:*:*:*:*:*:*:*
apache subversion 1.5.1 cpe:2.3:a:apache:subversion:1.5.1:*:*:*:*:*:*:*
apache subversion 1.5.2 cpe:2.3:a:apache:subversion:1.5.2:*:*:*:*:*:*:*
apache subversion 1.5.3 cpe:2.3:a:apache:subversion:1.5.3:*:*:*:*:*:*:*
apache subversion 1.5.4 cpe:2.3:a:apache:subversion:1.5.4:*:*:*:*:*:*:*
apache subversion 1.5.5 cpe:2.3:a:apache:subversion:1.5.5:*:*:*:*:*:*:*
apache subversion 1.5.6 cpe:2.3:a:apache:subversion:1.5.6:*:*:*:*:*:*:*
apache subversion 1.5.7 cpe:2.3:a:apache:subversion:1.5.7:*:*:*:*:*:*:*
apache subversion 1.5.8 cpe:2.3:a:apache:subversion:1.5.8:*:*:*:*:*:*:*
apache subversion 1.6.0 cpe:2.3:a:apache:subversion:1.6.0:*:*:*:*:*:*:*
apache subversion 1.6.1 cpe:2.3:a:apache:subversion:1.6.1:*:*:*:*:*:*:*
apache subversion 1.6.2 cpe:2.3:a:apache:subversion:1.6.2:*:*:*:*:*:*:*
apache subversion 1.6.3 cpe:2.3:a:apache:subversion:1.6.3:*:*:*:*:*:*:*
apache subversion 1.6.4 cpe:2.3:a:apache:subversion:1.6.4:*:*:*:*:*:*:*
apache subversion 1.6.5 cpe:2.3:a:apache:subversion:1.6.5:*:*:*:*:*:*:*
apache subversion 1.6.6 cpe:2.3:a:apache:subversion:1.6.6:*:*:*:*:*:*:*
apache subversion 1.6.7 cpe:2.3:a:apache:subversion:1.6.7:*:*:*:*:*:*:*
apache subversion 1.6.8 cpe:2.3:a:apache:subversion:1.6.8:*:*:*:*:*:*:*
apache subversion 1.6.9 cpe:2.3:a:apache:subversion:1.6.9:*:*:*:*:*:*:*
apache subversion 1.6.10 cpe:2.3:a:apache:subversion:1.6.10:*:*:*:*:*:*:*
apache subversion 1.6.11 cpe:2.3:a:apache:subversion:1.6.11:*:*:*:*:*:*:*
apache subversion 1.6.12 cpe:2.3:a:apache:subversion:1.6.12:*:*:*:*:*:*:*
apache subversion 1.6.13 cpe:2.3:a:apache:subversion:1.6.13:*:*:*:*:*:*:*
apache subversion 1.6.14 cpe:2.3:a:apache:subversion:1.6.14:*:*:*:*:*:*:*
apache subversion 1.6.15 cpe:2.3:a:apache:subversion:1.6.15:*:*:*:*:*:*:*
apache subversion 1.6.16 cpe:2.3:a:apache:subversion:1.6.16:*:*:*:*:*:*:*

References for CVE-2011-1921

URL Tags
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.html
http://secunia.com/advisories/44633 Vendor Advisory
http://secunia.com/advisories/44681 Vendor Advisory
http://secunia.com/advisories/44849
http://secunia.com/advisories/44888
http://secunia.com/advisories/45162
http://subversion.apache.org/security/CVE-2011-1921-advisory.txt Vendor Advisory
http://support.apple.com/kb/HT5130
http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGES
http://www.debian.org/security/2011/dsa-2251
http://www.mandriva.com/security/advisories?name=MDVSA-2011:106
http://www.redhat.com/support/errata/RHSA-2011-0862.html
http://www.securityfocus.com/bid/48091
http://www.securitytracker.com/id?1025619
http://www.ubuntu.com/usn/USN-1144-1
https://bugzilla.redhat.com/show_bug.cgi?id=709114
https://exchange.xforce.ibmcloud.com/vulnerabilities/67804
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18999
cvelogic Threat Intelligence