CVE-2017-1002157

EUVD-2019-0088
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H