Executive brief
Mercurial is a distributed version control system used to manage source code repositories. A vulnerability in the SSH peer component allows attackers to execute arbitrary commands on systems when cloning a repository with a specially crafted name, potentially leading to complete system compromise without requiring authentication.
Technical details
The vulnerability exists in the _validaterepo function in sshpeer, which insufficiently validates repository names passed to the clone command. An attacker can inject shell metacharacters into a repository name to execute arbitrary commands with the privileges of the user running the clone operation. The attack is network-accessible and requires no authentication or user interaction beyond initiating a clone operation. A successful exploit allows remote code execution. The vulnerability was fixed in version 3.2.4, with earlier versions (0.x through 3.2.3) affected.
Affected products
- Mercurial Mercurial before 3.2.4
Timeline
- 2015-03-31: disclosed: NVD publication date
- 2015: patched: Version 3.2.4 released with fix
- 2022-05-14: advisory: GHSA advisory published