CVE-2024-45720
HIGHApache Subversion <= 1.14.3 - OS Command Injection via Windows Command Line Argument Encoding
Title source: llmDescription
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed. All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue. Subversion is not affected on UNIX-like platforms.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://subversion.apache.org/security/CVE-2024-45720-advisory.txt
Scores
CVSS v3
8.2
EPSS
0.0007
EPSS Percentile
21.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
apache/subversion
< 1.14.4
Published
Oct 09, 2024
Tracked Since
Feb 18, 2026