PT-2019-6582 · Mercurial · Mercurial

Dave B

·

Publicado

2019-10-29

·

Atualizado

2022-04-21

·

CVE-2010-4237

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mercurial versions prior to 1.6.4
Description The issue allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack due to the failure to verify the Common Name field of SSL certificates.
Recommendations For versions prior to 1.6.4, update to version 1.6.4 or later to resolve the issue.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4237
GHSA-7GF7-7WX4-MXMW

Produtos afetados

Mercurial