Vulnerability Name: | CVE-2008-4297 (CCN-45229) | ||||||||
Assigned: | 2008-08-13 | ||||||||
Published: | 2008-08-13 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-4297 Source: SUSE Type: UNKNOWN SUSE-SR:2008:020 Source: MLIST Type: UNKNOWN [oss-security] 20080918 CVE Request (mercurial) Source: SECUNIA Type: UNKNOWN 32182 Source: CONFIRM Type: UNKNOWN http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0276 Source: CCN Type: OSVDB ID: 48318 Mercurial hgweb allowpull Permission Enforcement Weakness Source: BUGTRAQ Type: UNKNOWN 20080917 rPSA-2008-0276-1 mercurial mercurial-hgk Source: BID Type: UNKNOWN 31223 Source: CCN Type: BID-31223 Mercurial hgweb 'allowpull' Information Disclosure Vulnerability Source: CCN Type: Mercurial Web site Release Notes, Version 1.0.2 - 2008-08-13 Source: CONFIRM Type: UNKNOWN http://www.selenic.com/mercurial/wiki/index.cgi/WhatsNew#head-905b8adb3420a77d92617e06590055bd8952e02b Source: VUPEN Type: UNKNOWN ADV-2008-2604 Source: XF Type: UNKNOWN mercurial-allowpull-info-disclosure(45229) Source: XF Type: UNKNOWN mercurial-allowpull-info-disclosure(45229) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-2753 Source: SUSE Type: SUSE-SR:2008:020 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |