Executive brief
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
Affected products
- PyPI mercurial
Junglewise Threat Intelligence
CVE-2017-1000116 · Severity: low · CVSS 3 · Published 2017-10-05
Technologies: mercurial (PyPI). Vendors: PyPI.
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.