Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
References
Configurations
History
No history.
Information
Published : 2018-01-10 09:29
Updated : 2024-11-21 03:19
NVD link : CVE-2017-18026
Mitre link : CVE-2017-18026
CVE.ORG link : CVE-2017-18026
JSON object : View
Products Affected
redmine
- redmine
debian
- debian_linux
CWE