CollabNet develops version-control and agile-project-management software, with its vulnerability footprint concentrated in products such as Subversion and ScrumWorks that serve development teams. The recurring signal points to input-validation weaknesses characteristic of tools that process diverse user-supplied content and configuration data, with some disclosures carrying insufficient detail for comprehensive classification. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Collabnet over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2088HIGH contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacte | Jul 31, 2013 | 7.1 | 43 | NO | YES |
CVE-2012-2603MEDIUM The server in CollabNet ScrumWorks Pro before 6.0 allows remote authenticated users to gain privileges and obtain sensitive information via a modified desktop client. | Jun 8, 2012 | 6.5 | 22 | NO | NO |
CVE-2013-2112HIGH The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection. | Jul 31, 2013 | 7.8 | 21 | NO | NO |
CVE-2011-0410MEDIUM CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-dependent attackers to obtain sen | Jan 24, 2011 | 5.0 | 18 | NO | NO |
CVE-2013-1968MEDIUM Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name. | Jul 31, 2013 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Collabnet.
Media articles that mention a CVE ID that affects a product developed by Collabnet — matched by CVE ID, not by vendor name.