Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-18026

Опубликовано: 10 янв. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.

РелизСтатусПримечание
artful

released

3.3.1-4+deb9u1build0.17.10.1
bionic

not-affected

3.4.4-1
cosmic

not-affected

3.4.4-1
devel

DNE

disco

not-affected

3.4.4-1
eoan

not-affected

3.4.4-1
esm-apps/bionic

not-affected

3.4.4-1
esm-apps/focal

not-affected

3.4.4-1
esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]

Показывать по

EPSS

Процентиль: 73%
0.00747
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 8 лет назад

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.

CVSS3: 8.8
debian
около 8 лет назад

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does ...

CVSS3: 8.8
github
больше 3 лет назад

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.

EPSS

Процентиль: 73%
0.00747
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3