CVE-2024-45720

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 9, 2024
Updated: Feb 11, 2025
CWE ID 78

Summary

CVE-2024-45720 is a vulnerability affecting Subversion on Windows platforms. This issue arises due to a "best fit" character encoding conversion of command line arguments to Subversion's executables, leading to unexpected command line argument interpretation. Consequently, attackers can potentially inject arguments and execute other programs. All Subversion versions up to 1.14.3 are susceptible, and Windows users are advised to upgrade to version 1.14.4 to mitigate this risk. Importantly, Subversion remains unaffected on UNIX-like platforms.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache Subversion

Affected Vendors

  • Apache Corporation