CVE-2024-45720
published 2024-10-09CVE-2024-45720: On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.60%
44.9th percentile
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed.
All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue.
Subversion is not affected on UNIX-like platforms.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | < 1.14.4 | 1.14.4 |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.14.5-r0 | 1.14.5-r0 |
| apache | subversion | >= 0 < 1.14.5-r0 | 1.14.5-r0 |
| apache | subversion | >= 0 < 1.14.5-r0 | 1.14.5-r0 |
| apache | subversion | >= 0 < 1.14.4-r0 | 1.14.4-r0 |
| apache | subversion | >= 0 < 1.14.4-r0 | 1.14.4-r0 |
| apache | subversion | >= 0 < 1.14.4-r0 | 1.14.4-r0 |
| apache_software_foundation | apache_subversion | 1.0.0 – 1.14.3 | — |
| debian | subversion | — | — |
| msrc | azl3_subversion_1.14.3-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_subversion_1.14.2-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_apache8.2HIGH
vendor_debian8.2LOW
vendor_msrc8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Apache Subversion: Command line argument injection on Windows platforms
vendor_msrc·2024-10-08·CVSS 8.2
CVE-2024-45720 [HIGH] CWE-78 Apache Subversion: Command line argument injection on Windows platforms
Apache Subversion: Command line argument injection on Windows platforms
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Debian
CVE-2024-45720: subversion - On Windows platforms, a "best fit" character encoding conversion of command line...
vendor_debian·2024·CVSS 8.2
CVE-2024-45720 [HIGH] CVE-2024-45720: subversion - On Windows platforms, a "best fit" character encoding conversion of command line...
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed. All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue. Subversion is not affected on UNIX-like platforms.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Apache
Apache subversion: CVE-2024-45720
vendor_apache·CVSS 8.2
CVE-2024-45720 [HIGH] Apache subversion: CVE-2024-45720
Apache subversion: CVE-2024-45720
-advisory.txt [ PGP ] 1.0.0-1.10.8, 1.14.0-1.14.3 Subversion command line argument injection on Windows platforms
OSV
CVE-2024-45720: On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e
osv·2024-10-09·CVSS 7.8
CVE-2024-45720 [HIGH] CVE-2024-45720: On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed.
All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue.
Subversion is not affected on UNIX-like platforms.
GHSA
GHSA-86vm-fj76-qh69: On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e
ghsa_unreviewed·2024-10-09
CVE-2024-45720 [HIGH] CWE-78 GHSA-86vm-fj76-qh69: On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed.
All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue.
Subversion is not affected on UNIX-like platforms.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-09
Published