CVE-2017-9462
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
- Mercurial
- < 4.1.3
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 21.7% (97th percentile)
- Weakness
- CWE-732
- NVD status
- Modified
- Published
- 2017-06-06
CVE-2017-9462 at NVD
1 known exploit for CVE-2017-9462
Proof-of-concept code and exploit modules indexed by Sploitus