Executive brief
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
Affected products
- PyPI mercurial
Junglewise Threat Intelligence
CVE-2019-3902 · Severity: low · CVSS 3 · Published 2019-04-22
Technologies: mercurial (PyPI). Vendors: PyPI.
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.