Information disclosure in Mercurial - CVE-2018-1000132
Published: March 19, 2018 / Updated: March 21, 2018
Vulnerability identifier: #VU11150
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000132
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper access control. A remote attacker can gain access to potentially sensitive information.
The weakness exists due to improper access control. A remote attacker can gain access to potentially sensitive information.
Affected software
Mercurial
mercurial (Alpine package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
mercurial (Alpine package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
How to mitigate CVE-2018-1000132
Update to version 4.5.1.
mercurial (Alpine package) - update to 4.5.2-r0