CVE-2017-17536
Last modified
CVE-2017-17536 is a vulnerability of currently unknown severity. Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phacility | Phabricator | < 2017-11-10 |
References
- https://hackerone.com/reports/288704Issue Tracking, Third Party Advisory
- https://secure.phabricator.com/T13012Issue Tracking, Patch, Vendor Advisory
- https://hackerone.com/reports/288704Issue Tracking, Third Party Advisory
- https://secure.phabricator.com/T13012Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17536?
How severe is CVE-2017-17536?
How do I fix CVE-2017-17536?
Are you affected by CVE-2017-17536?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
