« List of all CVEs

CVE-2017-9462

Published: 6/6/2017 Last updated: 8/5/2024 Reserved: 6/6/2017

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

conf-hg

Products affected (1)

Product Vendor Version
n/a n/a 1.0.0

References (16)