id: PYSEC-2018-87 details: Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1. affected: - package: name: mercurial ecosystem: PyPI purl: pkg:pypi/mercurial ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 4.5.1 versions: - 0.8.1 - "0.9" - 0.9.1 - 0.9.2 - 0.9.3 - 0.9.4 - 0.9.5 - "1.0" - 1.0.1 - 1.0.2 - "1.1" - 1.1.1 - 1.1.2 - "1.2" - 1.2.1 - "1.3" - 1.3.1 - "1.4" - 1.4.1 - 1.4.2 - 1.4.3 - "1.5" - 1.5.1 - 1.5.2 - 1.5.3 - 1.5.4 - "1.6" - 1.6.1 - 1.6.2 - 1.6.3 - 1.6.4 - "1.7" - 1.7.1 - 1.7.2 - 1.7.3 - 1.7.5 - "1.8" - 1.8.1 - 1.8.2 - 1.8.3 - 1.8.4 - "1.9" - 1.9.1 - 1.9.2 - 1.9.3 - "2.0" - 2.0.1 - 2.0.2 - "2.1" - 2.1.1 - 2.1.2 - "2.2" - 2.2.2 - "2.3" - 2.4.1 - "2.5" - 2.5.1 - 2.5.2 - "2.6" - 2.6.1 - 2.6.2 - 2.6.3 - 2.7.0 - 2.7.1 - 2.7.2 - "2.8" - 2.8.1 - 2.8.2 - "2.9" - 2.9.1 - "3.0" - 3.0.1 - "3.1" - 3.1.1 - 3.1.2 - "3.2" - 3.2.1 - 3.2.2 - 3.2.3 - 3.2.4 - "3.3" - 3.3-rc - 3.3.1 - 3.3.2 - 3.3.3 - "3.4" - 3.4-rc - 3.4.1 - 3.4.2 - "3.5" - 3.5-rc - 3.5.1 - 3.5.2 - "3.6" - 3.6-rc - 3.6.1 - 3.6.2 - 3.6.3 - "3.7" - 3.7-rc - 3.7.1 - 3.7.2 - 3.7.3 - "3.8" - 3.8-rc - 3.8.1 - 3.8.2 - 3.8.3 - 3.8.4 - "3.9" - 3.9-rc - 3.9.1 - 3.9.2 - "4.0" - 4.0-rc - 4.0.1 - 4.0.2 - "4.1" - 4.1-rc - 4.1.1 - 4.1.2 - 4.1.3 - "4.2" - 4.2-rc - 4.2.1 - 4.2.2 - 4.2.3 - "4.3" - 4.3-rc - 4.3.1 - 4.3.2 - 4.3.3 - 4.3rc0 - "4.4" - 4.4-rc - 4.4.1 - 4.4.2 - 4.4rc0 - "4.5" - 4.5-rc - 4.5rc0 references: - type: WEB url: https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.5.1_.2F_4.5.2_.282018-03-06.29 - type: WEB url: https://lists.debian.org/debian-lts-announce/2018/03/msg00034.html - type: WEB url: https://lists.debian.org/debian-lts-announce/2018/07/msg00005.html - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2019:2276 - type: WEB url: https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html - type: ADVISORY url: https://github.com/advisories/GHSA-4mr4-7vjv-9hm6 aliases: - CVE-2018-1000132 - GHSA-4mr4-7vjv-9hm6 modified: "2021-08-27T03:22:07.192158Z" published: "2018-03-14T13:29:00Z"