PT-2024-31739 · Apache+1 · Apache Subversion+1

Orange Tsai

+1

·

Published

2024-10-08

·

Updated

2026-02-21

·

CVE-2024-45720

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache Subversion versions up to and including 1.14.3
Description: On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed. This issue affects Windows platforms only and does not impact UNIX-like platforms.
Recommendations: For Apache Subversion versions up to and including 1.14.3, upgrade to version 1.14.4, which fixes this issue.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17031
ALT-PU-2024-17033
ALT-PU-2024-17143
ALT-PU-2024-17145
BIT-SUBVERSION-2024-45720
CVE-2024-45720

Affected Products

Alt Linux
Apache Subversion