Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4387
HistoryJun 07, 2017 - 5:04 a.m.

Remote Code Execution (RCE)

2017-06-0705:04:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.03 Low

EPSS

Percentile

91.0%

Mecurial is vulnerable to remote code execution (RCE). The hg serve --stdio command allows a malicious user to launch the python debugger to execute arbitrary python code by using --debugger as the target repository.

CPENameOperatorVersion
mercurialle4.1.2