Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | mercurial | 1.0.1, 0.8.1, 0.9 |
Timeline
- Dec 7, 2017 CVE Published
- May 1, 2024 CVE Updated
References
- https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.4.1_.282017-11-07.29 url
- https://www.mercurial-scm.org/pipermail/mercurial-devel/2017-November/107333.html url
- https://bz.mercurial-scm.org/show_bug.cgi?id=5730 url
- https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2018-01-24-942834324.html advisory
- http://www.securityfocus.com/bid/102926 url
- https://lists.debian.org/debian-lts-announce/2017/12/msg00027.html advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00005.html advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00041.html advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html advisory