Back

HIGH

Mercurial: pathaudit: path traversal via symlink

Published Oct 4, 2017

Description

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

Affected products

Remediation

No remediation recorded yet.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 4, 2017
Updated Aug 5, 2024
Reserved Oct 3, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 10, 2017
ENISA EUVD
Assigner mitre
Published Oct 4, 2017
Updated Aug 5, 2024
Exploited since n/a
EUVD-2017-0070 GHSA-HVR9-WR9P-GRGR