VYPR
Medium severity5.9NVD Advisory· Published Oct 29, 2019· Updated Jun 16, 2026

CVE-2010-4237

CVE-2010-4237

Description

Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mercurialPyPI
< 1.6.41.6.4

Affected products

3
  • cpe:2.3:a:mercurial:mercurial:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mercurial:mercurial:*:*:*:*:*:*:*:*range: <1.6.4
    • (no CPE)range: 1.6.4
  • ghsa-coords
    Range: < 1.6.4

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.