---
title: "CVE-2021-28544\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2021-28544?format=md
keywords: index, follow
---

# CVE-2021-28544

Publication date 12 April 2021

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**4.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2021-28544?format=md#impact-score)

Toggle side navigation

## Description

Apache Subversion SVN authz protected copyfrom paths regression Subversion
servers reveal 'copyfrom' paths that should be hidden according to
configured path-based authorization (authz) rules. When a node has been
copied from a protected location, users with access to the copy can see the
'copyfrom' path of the original. This also reveals the fact that the node
was copied. Only the 'copyfrom' path is revealed; not its contents. Both
httpd and svnserve servers are vulnerable.

### From the Ubuntu Security Team

Evgeny Kotkov discovered that subversion servers did not properly
follow path-based authorization rules in certain cases. An attacker
could potentially use this issue to retrieve information about
private paths.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| subversion | 22.04 LTS jammy | Fixed 1.14.1-3ubuntu0.22.04.1 |
| 21.10 impish | Fixed 1.14.1-3ubuntu0.1 |
| 20.04 LTS focal | Fixed 1.13.0-3ubuntu0.1 |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

4.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 4.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28544)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-28544)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2021-28544)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2021-28544)

### Related Ubuntu Security Notices (USN)

+ [USN-5372-1](https://usn.ubuntu.com/USN-5372-1)
+ Subversion vulnerabilities
+ 12 April 2022

+ [USN-5450-1](https://usn.ubuntu.com/USN-5450-1)
+ Subversion vulnerabilities
+ 27 May 2022

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2021-28544>
