Apache · Apache Subversion · CVE-2024-46901
**Name of the Vulnerable Software and Affected Versions**
Apache Subversion versions prior to 1.14.5
**Description**
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod dav svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository.
**Recommendations**
For versions prior to 1.14.5, upgrade to version 1.14.5, which fixes this issue.
As a temporary workaround, consider restricting access to the mod dav svn module until a patch is available.
Avoid using mod dav svn to serve repositories until the issue is resolved.