BIT-subversion-2024-45720

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/subversion/BIT-subversion-2024-45720.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-subversion-2024-45720
Aliases
Published
2024-10-11T07:16:51.013Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed.

All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue.

Subversion is not affected on UNIX-like platforms.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / subversion

Package

Name
subversion
Purl
pkg:bitnami/subversion

Severity

  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0
Fixed
1.14.4