Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-4297

Опубликовано: 27 сент. 2008
Источник: debian
EPSS Низкий

Описание

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mercurialfixed1.0.1-5.1package
mercurialno-dsaetchpackage

Примечания

  • the package doesnt install this script by default but ships it with the examples

EPSS

Процентиль: 72%
0.00756
Низкий

Связанные уязвимости

ubuntu
почти 17 лет назад

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

redhat
около 17 лет назад

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

nvd
почти 17 лет назад

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

github
больше 3 лет назад

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

EPSS

Процентиль: 72%
0.00756
Низкий