Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4mr4-7vjv-9hm6

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

Mercurial Incorrect Access Control vulnerability

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

Пакеты

Наименование

mercurial

pip
Затронутые версииВерсия исправления

< 4.5.1

4.5.1

EPSS

Процентиль: 73%
0.00783
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 8 лет назад

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

CVSS3: 6.5
redhat
почти 8 лет назад

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

CVSS3: 9.1
nvd
почти 8 лет назад

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

CVSS3: 9.1
debian
почти 8 лет назад

Mercurial version 4.5 and earlier contains a Incorrect Access Control ...

suse-cvrf
почти 8 лет назад

Security update for mercurial

EPSS

Процентиль: 73%
0.00783
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-732