#VU98496 OS Command Injection in Subversion - CVE-2024-45720
Published: October 14, 2024
Subversion
Apache Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation during "best fit" character encoding conversion. A remote attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Note, the vulnerability affects Windows installations only.