QID 995369
Date Published: 2023-09-25
QID 995369: Python (Pip) Security Update for mercurial (GHSA-v2gw-x5jf-pgwv)
Directory traversal vulnerability in patch.py in Mercurial before 1.0.2 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v2gw-x5jf-pgwv for updates and patch information.
Vendor References
- GHSA-v2gw-x5jf-pgwv -
github.com/advisories/GHSA-v2gw-x5jf-pgwv
CVEs related to QID 995369
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v2gw-x5jf-pgwv | mercurial |
|