CVE-2018-1000132

Description

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.783

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-1000132 are fixed in Python-mercurial 4.5.1Windows
(RHSA-2019:2276)Moderate: security update mercurial-debuginfo-2.6.2-10.el7.x86_64.rpmLinux
Vulnerabilities CVE-2018-1000132 are fixed in Python-mercurial for linux 4.5.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234