CVE Vulnerabilities

CVE-2017-18026

Published: Jan 10, 2018 | Modified: Oct 03, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the –config and –debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a –config= or –debugger= substring, a related issue to CVE-2017-17536.

Affected Software

Name Vendor Start Version End Version
Redmine Redmine * 3.2.9 (excluding)
Redmine Redmine 3.3.0 (including) 3.3.6 (excluding)
Redmine Redmine 3.4.0 (including) 3.4.4 (excluding)

References