cbcvebase.
CVE-2024-45720
published 2024-10-09

CVE-2024-45720: On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.60%
44.9th percentile
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed. All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue. Subversion is not affected on UNIX-like platforms.

Affected

12 ranges
VendorProductVersion rangeFixed in
apachesubversion< 1.14.41.14.4
apachesubversion
apachesubversion>= 0 < 1.14.5-r01.14.5-r0
apachesubversion>= 0 < 1.14.5-r01.14.5-r0
apachesubversion>= 0 < 1.14.5-r01.14.5-r0
apachesubversion>= 0 < 1.14.4-r01.14.4-r0
apachesubversion>= 0 < 1.14.4-r01.14.4-r0
apachesubversion>= 0 < 1.14.4-r01.14.4-r0
apache_software_foundationapache_subversion1.0.0 – 1.14.3
debiansubversion
msrcazl3_subversion_1.14.3-2_on_azure_linux_3.0
msrccbl2_subversion_1.14.2-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_apache8.2HIGH
vendor_debian8.2LOW
vendor_msrc8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.