CVE-2008-4297
27.09.2008, 10:30
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.Enginsight
Vendor | Product | Version |
---|---|---|
mercurial | mercurial | 𝑥 ≤ 1.0.1 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration
References