Information disclosure in Mercurial - CVE-2018-1000132

 

Information disclosure in Mercurial - CVE-2018-1000132

Published: March 19, 2018 / Updated: March 21, 2018


Vulnerability identifier: #VU11150
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000132
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information on the target system.

The weakness exists due to improper access control. A remote attacker can gain access to potentially sensitive information.

Affected software

Mercurial
mercurial (Alpine package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing

How to mitigate CVE-2018-1000132

Update to version 4.5.1.

mercurial (Alpine package) - update to 4.5.2-r0

External References

Related Security Bulletins