In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mercurial | Feb 19, 2019 | Dec 7, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade mercurial | Nov 3, 2020 | Dec 7, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade mercurial | Apr 30, 2021 | Dec 7, 2017 |
| Oracle Solaris | — | Upgrade developer/versioning/mercurial to version 4.7.1-11.4.7.0.1.3.0 on Solaris 11.4Upgrade developer/versioning/mercurial-27 to version 4.7.1-11.4.7.0.1.3.0 on Solaris 11.4 | Mar 20, 2019 | Dec 7, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 3, 2017 |
| Suse | — | Upgrade mercurial | Dec 20, 2017 | Dec 7, 2017 |
| Ubuntu | — | Upgrade mercurial | Nov 19, 2024 | Dec 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub