Phabricator before 2017-11-10 does not block the –config and –debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a –config= or –debugger= substring.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phabricator | Phacility | * | 2017-11-10 (excluding) |
Phabricator | Ubuntu | artful | * |
Phabricator | Ubuntu | cosmic | * |
Phabricator | Ubuntu | esm-apps/xenial | * |
Phabricator | Ubuntu | upstream | * |
Phabricator | Ubuntu | xenial | * |
Phabricator | Ubuntu | zesty | * |