PT-2024-31739 · Apache+1 · Apache Subversion+1
Orange Tsai
+1
·
Published
2024-10-08
·
Updated
2026-02-21
·
CVE-2024-45720
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache Subversion versions up to and including 1.14.3
Description:
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed. This issue affects Windows platforms only and does not impact UNIX-like platforms.
Recommendations:
For Apache Subversion versions up to and including 1.14.3, upgrade to version 1.14.4, which fixes this issue.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Subversion