Back

CVE-2017-9800

CRITICAL

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

Published: Aug 11, 2017 Modified: Jun 17, 2026
CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (12)

Vendor Product Version
apache subversion *
apache subversion 1.9.0
apache subversion 1.9.1
apache subversion 1.9.2
apache subversion 1.9.3
apache subversion 1.9.4
apache subversion 1.9.5
apache subversion 1.9.6
apache subversion 1.10.0
apache subversion 1.10.0
apache subversion 1.10.0
apache subversion 1.10.0

GitHub Security Advisory GHSA-34wf-vr8w-7xh4

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 18.89%

Top 3% most likely to be exploited

Threat Score 44.9 / 100

Data Sources

NVD EPSS GitHub