Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.
| Score | Percentile |
|---|---|
| 0.60% | 69.44% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 9.1 | 3.0 | — |
|
| 9.3 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-4mr4-7vjv-9hm6 ↗ |
| CVE | CVE-2018-1000132 ↗ |
| CWE id | Name |
|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | mercurial | < 4.5.1 | 4.5.1 | — |