First published: Wed Jan 10 2018(Updated: )
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redmine Redmine | <3.2.9 | |
Redmine Redmine | >=3.3.0<3.3.6 | |
Redmine Redmine | >=3.4.0<3.4.4 | |
Debian Debian Linux | =9.0 | |
debian/redmine | 5.0.4-5 5.0.4-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18026 is a vulnerability in Redmine before versions 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 that allows remote attackers to execute arbitrary commands through the Mercurial adapter.
CVE-2017-18026 has a severity rating of 8.8 out of 10.
Redmine versions before 3.2.9, between 3.3.0 and 3.3.6, and between 3.4.0 and 3.4.4 are affected by CVE-2017-18026.
To fix CVE-2017-18026, it is recommended to upgrade Redmine to version 3.2.9, 3.3.6, or 3.4.4.
You can find more information about CVE-2017-18026 at the following references: [Redmine Issue #27516](https://www.redmine.org/issues/27516), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2017-18026).