Arbitrary Command Execution in Apache Subversion Clients
CVE-2017-9800
What is CVE-2017-9800?
The vulnerability in Apache Subversion allows attackers to execute arbitrary shell commands by crafting malicious svn+ssh:// URLs. Affected clients include all versions before 1.8.19, and 1.9.x before 1.9.7, extending to 1.10.0.x through 1.10.0-alpha3. This exploit can be triggered by malicious servers, users, or proxy servers, compromising the integrity of repositories and systems where vulnerable versions are used. Users are advised to update their Subversion clients to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Subversion 1.0.0 to 1.8.18
Apache Subversion 1.9.0 to 1.9.6
References
EPSS Score
55% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved