Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-54056.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-54056
Upstream
Published
2024-12-09T10:15:05Z
Modified
2026-04-21T04:35:27Z
Summary
CVE-2024-46901 affecting package subversion for versions less than 1.14.2-2
Details

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository.

All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue.

Repositories served via other access methods are not affected.

References

Affected packages

Azure Linux:2 / subversion

Package

Name
subversion
Purl
pkg:rpm/azure-linux/subversion

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.2-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-54056.json"