QID 981080
QID 981080: Python (pip) Security Update for mercurial (GHSA-ghjx-3jg5-h6r2)
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-ghjx-3jg5-h6r2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-ghjx-3jg5-h6r2 -
github.com/advisories/GHSA-ghjx-3jg5-h6r2
CVEs related to QID 981080
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ghjx-3jg5-h6r2 | mercurial |
|