2024-12-15 03:03:56 +00:00

64 lines
2.6 KiB
JSON

{
"id": "CVE-2024-46901",
"sourceIdentifier": "security@apache.org",
"published": "2024-12-09T10:15:05.230",
"lastModified": "2024-12-09T10:15:05.230",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository.\n\nAll versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue.\n\nRepositories served via other access methods are not affected."
},
{
"lang": "es",
"value": "La validaci\u00f3n insuficiente de los nombres de archivo con respecto a los caracteres de control en Apache Subversion repositories que se sirven a trav\u00e9s de mod_dav_svn permite que los usuarios autenticados con acceso de confirmaci\u00f3n confirmen una revisi\u00f3n da\u00f1ada, lo que genera interrupciones para los usuarios del repositorio. Todas las versiones de Subversion hasta Subversion 1.14.4 incluida se ven afectadas si se sirven repositorios a trav\u00e9s de mod_dav_svn. Se recomienda a los usuarios que actualicen a la versi\u00f3n 1.14.5, que soluciona este problema. Los repositorios que se sirven a trav\u00e9s de otros m\u00e9todos de acceso no se ven afectados."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@apache.org",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
"baseScore": 3.1,
"baseSeverity": "LOW",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 1.6,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "security@apache.org",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-116"
}
]
}
],
"references": [
{
"url": "https://subversion.apache.org/security/CVE-2024-46901-advisory.txt",
"source": "security@apache.org"
}
]
}