CVE-2017-18026: High severity redmine vulnerability
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-18026?
CVE-2017-18026 is a vulnerability in Redmine before versions 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 that allows remote attackers to execute arbitrary commands through the Mercurial adapter.
How severe is CVE-2017-18026?
CVE-2017-18026 has a severity rating of 8.8 out of 10.
Which software versions are affected by CVE-2017-18026?
Redmine versions before 3.2.9, between 3.3.0 and 3.3.6, and between 3.4.0 and 3.4.4 are affected by CVE-2017-18026.
How can I fix CVE-2017-18026?
To fix CVE-2017-18026, it is recommended to upgrade Redmine to version 3.2.9, 3.3.6, or 3.4.4.
Where can I find more information about CVE-2017-18026?
You can find more information about CVE-2017-18026 at the following references: [Redmine Issue #27516](https://www.redmine.org/issues/27516), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2017-18026).