Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536
Published Jan 10, 2018
8.8
HIGHCVSS 3.0
EPSS 2.83%
Description
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.83% (0.02825) | 86.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.88% (0.02879) | 84.98th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.79% (0.00787) | 72.17th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.73% (0.00726) | 81.32th | v3 (v2023.03.01) |
| Apr 3, 2024 | 0.73% (0.00726) | 80.30th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.73% (0.00726) | 78.30th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.06% (0.01065) | 81.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.32% (0.01319) | 71.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.32% (0.01319) | 44.98th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.17% (0.03168) | 65.23th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.17% (0.03168) | 0.00th | v1 |
No CWE recorded.
References (6)
- https://github.com/redmine/redmine/commit/58ed8655136ff2fe5ff7796859bf6a399c76c678 x_refsource_MISCPatchThird Party Advisory
- https://github.com/redmine/redmine/commit/9d797400eaec5f9fa7ba9507c82d9c18cb91d02e x_refsource_MISCPatchThird Party Advisory
- https://github.com/redmine/redmine/commit/ca87bf766cdc70179cb2dce03015d78ec9c13ebd x_refsource_MISCPatchThird Party Advisory
- https://www.debian.org/security/2018/dsa-4191 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.redmine.org/issues/27516 x_refsource_MISCPermissions Required
- https://www.redmine.org/projects/redmine/wiki/Security_Advisories x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/redmine/redmine/commit/58ed8655136ff2fe5ff7796859bf6a399c76c678 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/redmine/redmine/commit/9d797400eaec5f9fa7ba9507c82d9c18cb91d02e | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/redmine/redmine/commit/ca87bf766cdc70179cb2dce03015d78ec9c13ebd | x_refsource_MISCPatchThird Party Advisory | |
| https://www.debian.org/security/2018/dsa-4191 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.redmine.org/issues/27516 | x_refsource_MISCPermissions Required | |
| https://www.redmine.org/projects/redmine/wiki/Security_Advisories | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.