CVE-2018-1000132

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mercurial:mercurial:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:39

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2019:2276 - () https://access.redhat.com/errata/RHSA-2019:2276 -
References () https://lists.debian.org/debian-lts-announce/2018/03/msg00034.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2018/03/msg00034.html - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2018/07/msg00005.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2018/07/msg00005.html - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html - () https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html -
References () https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.5.1_.2F_4.5.2_.282018-03-06.29 - Release Notes, Vendor Advisory () https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.5.1_.2F_4.5.2_.282018-03-06.29 - Release Notes, Vendor Advisory

Information

Published : 2018-03-14 13:29

Updated : 2024-11-21 03:39


NVD link : CVE-2018-1000132

Mitre link : CVE-2018-1000132

CVE.ORG link : CVE-2018-1000132


JSON object : View

Products Affected

debian

  • debian_linux

mercurial

  • mercurial
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource