Command Execution Vulnerability in Redmine by Redmine
CVE-2017-18026
8.8HIGH
What is CVE-2017-18026?
An oversight in Redmine's handling of command-line flags allows remote attackers to execute arbitrary commands through the Mercurial hg program. This vulnerability manifests when an attacker constructs a branch name that begins with the unsafe substrings '--config=' or '--debugger='. Such malformed input bypasses security checks, enabling the execution of commands with harmful implications. The flaw affects multiple versions of Redmine prior to their respective patches in 3.2.9, 3.3.6, and 3.4.4, and it is related to a previous security issue identified in CVE-2017-17536.
