Junglewise Threat Intelligence

CVE-2017-1000115: PYSEC-2017-88 - Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the reposito

CVE-2017-1000115 · Severity: low · CVSS 3 · Published 2017-10-05

Technologies: mercurial (PyPI). Vendors: PyPI.

Executive brief

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

Affected products

  • PyPI mercurial

Related threats