Executive brief
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
Affected products
- PyPI mercurial
Junglewise Threat Intelligence
CVE-2017-1000115 · Severity: low · CVSS 3 · Published 2017-10-05
Technologies: mercurial (PyPI). Vendors: PyPI.
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository