GCVE-VVD-MAGEIA-2017-282
Advisory Published
Vulnetix · Advisory published August 19, 2017
Mercurial was not sanitizing hostnames passed to ssh, allowing shell injection attacks by specifying a hostname starting with -oProxyCommand.

Affected Products

VendorProductVersionsPlatforms
Mageiamercurial0 (affected), 4.1.3-1.1.mga6 (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.