CVE Published: 22/04/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: redhat |
Vendor: The Mercurial Project |
Product: mercurial Status : PUBLISHED
CVE-2019-3902 Description
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial\'s path-checking logic and write files outside a repository.