Logo
vulnerabilityCVE-2024-45720
Name
CVE-2024-45720
Source
NVD ( link)Debian ( link)
Description
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed. All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue. Subversion is not affected on UNIX-like platforms.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
subversion
False Positive

Vulnerability Ratings#


8.2
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.14.5
Not Affected
buildroot
master
1.14.5
Not Affected
openwrt
master
1.14.5-r1
Not Affected
openwrt
openwrt-25.12
1.14.5-r1
Not Affected
yocto
kirkstone
1.14.2
Not Affected
yocto
master
1.14.5
Not Affected