Websvn · Websvn · CVE-2021-32305
Name of the Vulnerable Software and Affected Versions:
WebSVN versions prior to 2.6.1
Description:
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the `search` parameter.
Recommendations:
For versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the search functionality until a patch is available. Avoid using the `search` parameter with untrusted input in the affected API endpoint until the issue is resolved.