Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mq66-vcfc-8246

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Mercurial Path Traversal/Link Following vulnerability

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

Пакеты

Наименование

mercurial

pip
Затронутые версииВерсия исправления

< 4.9

4.9

EPSS

Процентиль: 73%
0.00749
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22
CWE-59

Связанные уязвимости

CVSS3: 5.1
ubuntu
почти 7 лет назад

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

CVSS3: 5.1
redhat
почти 7 лет назад

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

CVSS3: 5.1
nvd
почти 7 лет назад

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

CVSS3: 5.1
debian
почти 7 лет назад

A flaw was found in Mercurial before 4.9. It was possible to use symli ...

suse-cvrf
больше 5 лет назад

Security update for mercurial

EPSS

Процентиль: 73%
0.00749
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22
CWE-59