# Vuln Title: The CollabNet Subversion Edge does not protect against brute# forcing accounts## Date: 28.06.2015# Author: otr# Software Link: https://www.open.collab.net/downloads/svnedge# Vendor: CollabNet# Version: 4.0.11# Tested on: Fedora Linux# Type: Lack of defensive measures## Risk: Medium# Status: public/fixed# Fixed versions: 5.0Timeline:2014-10-09 Flaw Discovered2014-10-20 Vendor contacted2014-10-21 Vendor response2014-12-08 Vendor fix proposal2014-12-08 Extension of embargo to 19.4.20152015-05-04 Extension of embargo until release of version 5.02015-05-18 Release of version 5.0 and public disclosure
# Vuln Title: The CollabNet Subversion Edge Management Frontend does not# implement clickjacking protection## Date: 28.06.2015# Author: otr# Software Link: https://www.open.collab.net/downloads/svnedge# Vendor: CollabNet# Version: 4.0.11# Tested on: Fedora Linux# Type: Clickjacking## Risk: Medium# Status: public/fixed# Fixed version: 5.0Timeline:2014-10-09 Flaw Discovered2014-10-20 Vendor contacted2014-10-21 Vendor response2014-12-08 Vendor fix proposal2014-12-08 Extension of embargo to 19.4.20152015-05-04 Extension of embargo until release of version 5.02015-05-18 Release of version 5.0 and public disclosure
# Vuln Title: The CollabNet Subversion Edge management frontend login page# password field has autocomplete enabled## Date: 28.06.2015# Author: otr# Software Link: https://www.open.collab.net/downloads/svnedge# Vendor: CollabNet# Version: 4.0.11# Tested on: Fedora Linux# Type: Lack of defensive measures## Risk: Low# Status: public/fixed# Fixed version: 5.0# https://ctf.open.collab.net/sf/wiki/do/viewPage/projects.svnedge/wiki/Release_5.0.0Timeline:2014-10-09 Flaw Discovered2014-10-20 Vendor contacted2014-10-21 Vendor response2014-12-08 Vendor fix proposal2014-12-08 Extension of embargo to 19.4.20152015-05-04 Extension of embargo until release of version 5.02015-05-18 Release of version 5.0 and public disclosure
# Vuln Title: The CollabNet Subversion Edge Management Frontend does not# implement a strong password policy## Date: 28.06.2015# Author: otr# Software Link: https://www.open.collab.net/downloads/svnedge# Vendor: CollabNet# Version: 4.0.11# Tested on: Fedora Linux# Type: Lack of defensive measures## Risk: Medium# Status: public/fixed# Fixed version: 5.0Timeline:2014-10-09 Flaw Discovered2014-10-20 Vendor contacted2014-10-21 Vendor response2014-12-08 Vendor fix proposal2014-12-08 Extension of embargo to 19.4.20152015-05-04 Extension of embargo until release of version 5.02015-05-18 Release of version 5.0 and public disclosure
# Vuln Title: The CollabNet Subversion Edge Management Frontend does not implement XSRF protection tokens## Date: 28.06.2015# Author: otr# Software Link: https://www.open.collab.net/downloads/svnedge# Vendor: CollabNet# Version: 4.0.11# Tested on: Fedora Linux# Type: XSRF## Risk: Low# Status: public/fixed# Fixed version: 5.0Timeline:2014-10-09 Flaw Discovered2014-10-20 Vendor contacted2014-10-21 Vendor response2014-12-08 Vendor fix proposal2014-12-08 Extension of embargo to 19.4.20152015-05-04 Extension of embargo until release of version 5.02015-05-18 Release of version 5.0 and public disclosure
# Vuln Title: The CollabNet Subversion Edge stores passwords as unsalted MD5 hashes# Date: 28.06.2015# Author: otr# Software Link: https://www.open.collab.net/downloads/svnedge# Vendor: CollabNet# Version: 4.0.11# Tested on: Fedora Linux# Type: Insecure password storage# Risk: Medium# Status: public/fixed# Fixed version: 5.0Timeline:2014-10-09 Flaw Discovered2014-10-20 Vendor contacted2014-10-21 Vendor response2014-12-08 Vendor fix proposal2014-12-08 Extension of embargo to 19.4.20152015-05-04 Extension of embargo until release of version 5.02015-05-18 Release of version 5.0 and public disclosure