Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1002153

Опубликовано: 06 окт. 2017
Источник: debian

Описание

Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kojifixed1.16.0-1package
kojifixed1.10.0-1+deb9u1stretchpackage

Примечания

  • https://pagure.io/koji/issue/563

  • https://pagure.io/koji/c/ba7b5a3cbed11ade11c3af5e834c9a6de4f6d7c3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.

CVSS3: 7.5
nvd
больше 8 лет назад

Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.

CVSS3: 7.5
github
больше 3 лет назад

Koji blacklisted paths workaround