CVE-2008-4297
EUVD-2008-428027.09.2008, 10:30
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mercurial | mercurial | 𝑥 ≤ 1.0.1 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
References