CVE-2024-45720
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Oct 9, 2024
Updated: Feb 11, 2025
CWE ID 78
Summary
CVE-2024-45720 is a vulnerability affecting Subversion on Windows platforms. This issue arises due to a "best fit" character encoding conversion of command line arguments to Subversion's executables, leading to unexpected command line argument interpretation. Consequently, attackers can potentially inject arguments and execute other programs. All Subversion versions up to 1.14.3 are susceptible, and Windows users are advised to upgrade to version 1.14.4 to mitigate this risk. Importantly, Subversion remains unaffected on UNIX-like platforms.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Apache Subversion
Affected Vendors
- Apache Corporation