CVE-2018-1000132

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mercurial:mercurial:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-03-14 13:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-1000132

Mitre link : CVE-2018-1000132

CVE.ORG link : CVE-2018-1000132


JSON object : View

Products Affected

mercurial

  • mercurial

debian

  • debian_linux
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource