Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13676
HistoryApr 23, 2019 - 8:10 a.m.

Arbitrary File Write

2019-04-2308:10:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

61.3%

mercurial is vulnerable to arbitrary file write attacks. The vulnerability is possible by using symlinks and subrepositories to bypass the validation of path checking, allowing the writing of files outside of the repository.