Lucene search

K
redhatcveRedhat.comRH:CVE-2019-3902
HistoryApr 18, 2019 - 5:19 p.m.

CVE-2019-3902

2019-04-1817:19:51
redhat.com
access.redhat.com
8

0.002 Low

EPSS

Percentile

61.2%

Starting with version 1.5.3, Mercurial allows environment variable expansion on path names for sub repositories when creating it or cloning a parent repository, but it doesn’t validate whether the final path name outside the repository root directory. An attacker can leverage this weakness using a combination of symbolic links and environment variables to craft a tampered repository, leading Mercurial to write files outside the repository as long the destination location is empty.