Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository.
All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue.
Repositories served via other access methods are not affected.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 09 Dec 2024 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue. Repositories served via other access methods are not affected. | |
Title | Apache Subversion: mod_dav_svn denial-of-service via control characters in paths | |
Weaknesses | CWE-116 CWE-20 |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-12-09T09:36:52.445Z
Updated: 2024-12-09T15:23:24.851Z
Reserved: 2024-09-13T04:50:02.877Z
Link: CVE-2024-46901
Vulnrichment
Updated: 2024-12-09T15:23:19.352Z
NVD
Status : Received
Published: 2024-12-09T10:15:05.230
Modified: 2024-12-09T10:15:05.230
Link: CVE-2024-46901
Redhat
No data.