CVE-2017-18026
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
Redmine en versiones anteriores a la 3.2.9, 3.3.x anteriores a 3.3.6 y 3.4.x anteriores a 3.4.4 no bloquea los flags --config y --debugger en el programa Mercurial hg, lo que permite que los atacantes remotos ejecuten comandos arbitrarios (mediante el adaptador Mercurial) por medio de vectores que involucran una rama cuyo nombre empieza con una subcadena --config= o --debugger=. Esta vulnerabilidad está relacionada con CVE-2017-17536.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-10 CVE Reserved
- 2018-01-10 CVE Published
- 2023-08-06 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2018/dsa-4191 | 2019-10-03 | |
https://www.redmine.org/projects/redmine/wiki/Security_Advisories | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redmine Search vendor "Redmine" | Redmine Search vendor "Redmine" for product "Redmine" | < 3.2.9 Search vendor "Redmine" for product "Redmine" and version " < 3.2.9" | - |
Affected
| ||||||
Redmine Search vendor "Redmine" | Redmine Search vendor "Redmine" for product "Redmine" | >= 3.3.0 < 3.3.6 Search vendor "Redmine" for product "Redmine" and version " >= 3.3.0 < 3.3.6" | - |
Affected
| ||||||
Redmine Search vendor "Redmine" | Redmine Search vendor "Redmine" for product "Redmine" | >= 3.4.0 < 3.4.4 Search vendor "Redmine" for product "Redmine" and version " >= 3.4.0 < 3.4.4" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|