CVE-2024-46901

Severity
4.3MEDIUM
EPSS
5.8%
top 9.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateJan 15

Description

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue. Repositories served via other access methods are not

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.6 | Impact: 1.4

Affected Packages4 packages

NVDapache/subversion< 1.14.5
Alpinesubversion< 1.14.5-r0+5
Debiansubversion< 1.14.1-3+deb11u2+3

Also affects: Debian Linux 11.0

🔴Vulnerability Details

4
OSV
CVE-2024-46901: Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users wi2024-12-09
OSV
CVE-2024-46901: Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users wi2024-12-09
GHSA
GHSA-53gr-8h72-9w7p: Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users wi2024-12-09
CVEList
Apache Subversion: mod_dav_svn denial-of-service via control characters in paths2024-12-09

📋Vendor Advisories

7
Oracle
Oracle Oracle Communications Risk Matrix: Core (Apache Subversion) — CVE-2024-469012026-01-15
Ubuntu
Apache Subversion vulnerability2025-10-16
Ubuntu
Apache Subversion vulnerability2025-10-13
Microsoft
Apache Subversion: mod_dav_svn denial-of-service via control characters in paths2024-12-10
Red Hat
Subversion: Apache Subversion: mod_dav_svn denial-of-service via control characters in paths2024-12-09
CVE-2024-46901 (MEDIUM CVSS 4.3) | Insufficient validation of filename | cvebase.io