Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-1331-1 | mercurial security update |
![]() |
DLA-1414-1 | mercurial security update |
![]() |
DLA-2293-1 | mercurial security update |
![]() |
EUVD-2018-0094 | Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1. |
![]() |
GHSA-4mr4-7vjv-9hm6 | Mercurial Incorrect Access Control vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:33:49.240Z
Reserved: 2018-03-14T00:00:00
Link: CVE-2018-1000132

No data.

Status : Modified
Published: 2018-03-14T13:29:00.407
Modified: 2024-11-21T03:39:45.083
Link: CVE-2018-1000132


No data.