pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
2018-08-15T17:29:00.407
2024-11-21T03:42:17.943
Modified
CVSSv3.0: 6.8 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pulpproject | pulp | ≤ 2.16.0 | Yes |
Application | pulpproject | pulp | 2.16.1 | Yes |
Application | pulpproject | pulp | 2.16.2 | Yes |
Application | pulpproject | pulp | 2.16.4 | Yes |