Incorrect Permission Assignment for Critical Resource
Affecting mercurial package, versions <3.1.2-2+deb8u5
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.
References
CVSS Score
9.1
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityNone
- CVE
- CVE-2018-1000132
- CWE
- CWE-732
- Snyk ID
- SNYK-DEBIAN8-MERCURIAL-311112
- Disclosed
- 14 Mar, 2018
- Published
- 14 Mar, 2018