All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue.
Repositories served via other access methods are not affected.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4127-1 | subversion security update |
Ubuntu USN |
USN-7818-2 | Apache Subversion vulnerability |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache subversion Debian Debian debian Linux |
|
| CPEs | cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apache
Apache subversion Debian Debian debian Linux |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Apr 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 16 Jan 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 09 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Dec 2024 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue. Repositories served via other access methods are not affected. | |
| Title | Apache Subversion: mod_dav_svn denial-of-service via control characters in paths | |
| Weaknesses | CWE-116 CWE-20 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-13T21:02:57.347Z
Reserved: 2024-09-13T04:50:02.877Z
Link: CVE-2024-46901
Updated: 2025-04-13T21:02:57.347Z
Status : Analyzed
Published: 2024-12-09T10:15:05.230
Modified: 2025-07-15T16:35:39.093
Link: CVE-2024-46901
OpenCVE Enrichment
Updated: 2025-07-12T22:09:29Z
Debian DLA
Ubuntu USN