CVE-2014-9462: Mercurial vulnerable to arbitrary command execution via a crafted repository name in a clone command
(updated )
The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
References
Detect and mitigate CVE-2014-9462 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →