CRITICAL
mercurial: HTTP server permissions bypass
Published Mar 14, 2018
9.3
CRITICALCVSS 4.0
EPSS 2.62%
Description
Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.
Affected products
No data.
Configuration 2
OR
- 7.0
- 8.0
No data.
Red Hat Enterprise Linux 7
mercurial-0:2.6.2-10.el7
Fixed · RHSA-2019:2276
Red Hat Enterprise Linux 6
mercurial
Will not fix
Red Hat Enterprise Linux 8
mercurial
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | mercurial-0:2.6.2-10.el7 | Fixed | RHSA-2019:2276 |
| Red Hat Enterprise Linux 6 | mercurial | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | mercurial | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/errata/RHSA-2019:2276 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-1000132 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1553265 Issue Tracking
- https://github.com/advisories/GHSA-4mr4-7vjv-9hm6 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/mercurial/PYSEC-2018-87.yaml
- https://lists.debian.org/debian-lts-announce/2018/03/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00005.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000132
- https://www.cve.org/CVERecord?id=CVE-2018-1000132
- https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.5.1_.2F_4.5.2_.282018-03-06.29 x_refsource_CONFIRMRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:2276 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2018-1000132 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1553265 | Issue Tracking | |
| https://github.com/advisories/GHSA-4mr4-7vjv-9hm6 | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/mercurial/PYSEC-2018-87.yaml | ||
| https://lists.debian.org/debian-lts-announce/2018/03/msg00034.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00005.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000132 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000132 | ||
| https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.5.1_.2F_4.5.2_.282018-03-06.29 | x_refsource_CONFIRMRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 14, 2018
Updated Aug 5, 2024
Reserved Mar 14, 2018
Link CVE-2018-1000132
CISA Vulnrichment
GHSA-4MR4-7VJV-9HM6 Updated n/a