Vulnerability Description
Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phacility | Phabricator | < 2017-11-10 |
References
- https://hackerone.com/reports/288704Issue TrackingThird Party Advisory
- https://secure.phabricator.com/T13012Issue TrackingPatchVendor Advisory
- https://hackerone.com/reports/288704Issue TrackingThird Party Advisory
- https://secure.phabricator.com/T13012Issue TrackingPatchVendor Advisory
FAQ
What is CVE-2017-17536?
CVE-2017-17536 is a vulnerability with a CVSS score of 8.8 (HIGH). Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a bran...
How severe is CVE-2017-17536?
CVE-2017-17536 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17536?
Check the references section above for vendor advisories and patch information. Affected products include: Phacility Phabricator.