CVE-2018-1000132

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
mercurialmercurial
𝑥
< 4.5.1
debiandebian_linux
7.0
debiandebian_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mercurial
bookworm
6.3.2-1
fixed
bullseye
5.6.1-4
fixed
sid
6.8.2-1
fixed
trixie
6.8.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mercurial
artful
ignored
bionic
not-affected
cosmic
not-affected
trusty
Fixed 2.8.2-1ubuntu1.4
released
xenial
Fixed 3.7.3-1ubuntu1.1
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
emacs-mercurial
RHEL 7
0:2.6.2-10.el7
fixed
emacs-mercurial-el
RHEL 7
0:2.6.2-10.el7
fixed
mercurial
RHEL 7
0:2.6.2-10.el7
fixed
mercurial-hgk
RHEL 7
0:2.6.2-10.el7
fixed