Description
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9Complexity: Low
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-rw83-rp96-92cm: Mercurial before 1↗2022-05-02 ▶ OSVCVE-2008-4297: Mercurial before 1↗2008-09-27 ▶ CVEListCVE-2008-4297: Mercurial before 1↗2008-09-27 ▶ 📋Vendor Advisories
2Red Hatmercurial: missing allowpull permission check in hgweb↗2008-08-13 ▶ DebianCVE-2008-4297: mercurial - Mercurial before 1.0.2 does not enforce the allowpull permission setting for a p...↗2008 ▶ 💬Community
4BugzillaCVE-2008-4297 mercurial [epel-5]↗2008-09-29 ▶ BugzillaCVE-2008-2942 CVE-2008-4297 mercurial: multiple security issues [Fedora 8]↗2008-09-29 ▶ BugzillaCVE-2008-4297 mercurial: missing allowpull permission check in hgweb↗2008-09-29 ▶ BugzillaCVE-2008-4297 mercurial [epel-4]↗2008-09-29 ▶