Logo
componentsubversion
Name
subversion
Version
1.14.2
Type
library
Description
Subversion (svn) version control system client
Licenses
Apache-2.0 & MIT
PURL
-
CPE
cpe:2.3:*:apache:subversion:1.14.2:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.14.5
scarthgap
1.14.3

Patches#


#
Title
Author
Resolve
1
Fix CVE-2024-46901
Jiaying Song <jiaying.song.cn@windriver.com>
CVE-2024-46901
2
Patch #2
Hongxu Jia <hongxu.jia@windriver.com>

Vulnerabilities#


Name
Analysis
Description
Patched
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue. Repositories served via other access methods are not affected.