Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3pmw-h7j4-rf54

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Mercurial vulnerable to arbitrary command execution via a crafted repository name in a clone command

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

Пакеты

Наименование

mercurial

pip
Затронутые версииВерсия исправления

< 3.2.4

3.2.4

EPSS

Процентиль: 79%
0.01289
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 11 лет назад

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

redhat
около 11 лет назад

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

nvd
почти 11 лет назад

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

debian
почти 11 лет назад

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows ...

suse-cvrf
почти 11 лет назад

Security update for mercurial

EPSS

Процентиль: 79%
0.01289
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20