cbcvebase.
CVE-2019-3902
published 2019-04-22

CVE-2019-3902: A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside…

PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
1.41%
69.8th percentile
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianmercurial< mercurial 4.9-1 (bookworm)mercurial 4.9-1 (bookworm)
mercurialmercurial< 4.94.9
mercurialmercurial>= 0 < 4.9-14.9-1
mercurialmercurial>= 0 < 4.9-14.9-1
mercurialmercurial>= 0 < 4.9-14.9-1
mercurialmercurial>= 0 < 4.9-14.9-1
mercurialmercurial>= 0 < 4.94.9
mercurialmercurial>= 0 < 4.5.3-1ubuntu2.24.5.3-1ubuntu2.2
mercurialmercurial>= 0 < 2.8.2-1ubuntu1.4+esm12.8.2-1ubuntu1.4+esm1
mercurialmercurial>= 0 < 3.7.3-1ubuntu1.2+esm23.7.3-1ubuntu1.2+esm2
redhatenterprise_linux
the_mercurial_projectmercurial

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.