Skip to content

Commit

Permalink
docs(CHANGES): Detail CVE-2022-21187 for 0.11.1
Browse files Browse the repository at this point in the history
  • Loading branch information
tony committed Mar 14, 2022
1 parent 9f9626b commit 3e6427c
Showing 1 changed file with 7 additions and 3 deletions.
10 changes: 7 additions & 3 deletions CHANGES
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,15 @@

## libvcs 0.11.1 (2022-03-12)

### Potential command injection via mercurial URLs
### CVE-2022-21187: Command Injection with mercurial repositories

- By setting a mercurial URL with an alias it is possible to execute arbitrary shell commands via
`.obtain()` or in the case of uncloned destinations, `.update_repo()`. (#306, credit: Alessio
Della Libera)
`.obtain()` or in the case of uncloned destinations, `.update_repo()`.
([#306](https://github.com/vcs-python/libvcs/pull/306), credit: Alessio Della Libera)

See also: [cve.mitre.org](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21187),
[nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2022-21187),
[snyk](https://security.snyk.io/vuln/SNYK-PYTHON-LIBVCS-2421204).

### Development

Expand Down

0 comments on commit 3e6427c

Please sign in to comment.