CVE-2018-10917
15.08.2018, 17:29
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
Vendor | Product | Version |
---|---|---|
pulpproject | pulp | 𝑥 ≤ 2.16.0 |
pulpproject | pulp | 2.16.1 |
pulpproject | pulp | 2.16.2 |
pulpproject | pulp | 2.16.4 |
𝑥
= Vulnerable software versions