GCVE-VVD-MAGEIA-2017-331
Advisory Published
Vulnetix · Advisory published September 7, 2017
Mercurial was not sanitizing hostnames passed to ssh, allowing shell injection attacks by specifying a hostname starting with -oProxyCommand.

Affected Products

VendorProductVersionsPlatforms
Mageiamercurial0 (affected), 3.1.1-5.5.mga5 (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.