Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Subversion clients 输入验证错误漏洞
Vulnerability Description
Apache Subversion clients是美国阿帕奇(Apache)软件基金会的一套开源的版本控制系统,该系统可兼容并发版本系统(CVS)。 Apache Subversion clients中存在安全漏洞。攻击者可通过构造恶意的svn+ssh:// URL利用该漏洞执行任意shell命令。以下版本受到影响:Subversion clients 1.8.19之前的版本,1.9.7之前的1.9.x版本,1.10.0.x至1.10.0-alpha3版本。
CVSS Information
N/A
Vulnerability Type
N/A