Loading...
Loading...
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.
September 27, 2008
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-4297
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.