vendor:
TortoiseSVN
by:
Vulnerability Laboratory
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: TortoiseSVN
Affected Version From: TortoiseSVN v1.12.1
Affected Version To: TortoiseSVN v1.12.1
Patch Exists: YES
Related CWE: CVE-2019-14422
CPE: a:tortoisesvn:tortoisesvn:1.12.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
TortoiseSVN v1.12.1 – Remote Code Execution Vulnerability
A remote code execution vulnerability has been discovered in the official TortoiseSVN v1.12.1 software. The vulnerability allows remote attackers to execute code on the vulnerable application. The vulnerability is located in the `svn.exe` module of the software. Remote attackers can execute code on the vulnerable application to compromise the application or connected system.
Mitigation:
Update to version 1.12.2