6.4
CVSSv2

CVE-2018-1000132

Published: 14/03/2018 Updated: 31/07/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Mercurial version 4.5 and previous versions contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

Vulnerable Product Search on Vulmon Subscribe to Product

mercurial mercurial

debian debian linux 7.0

debian debian linux 8.0

Vendor Advisories

Synopsis Moderate: mercurial security update Type/Severity Security Advisory: Moderate Topic An update for mercurial is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score ...
Debian Bug report logs - #892964 mercurial: CVE-2018-1000132 Package: src:mercurial; Maintainer for src:mercurial is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 14 Mar 2018 21:33:01 UTC Severity: grave Tags: security, ...
Mercurial version 45 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access This attack appear to be exploitable via network connectivity This vulnerability appears to have been fixed in 451 ...