Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-574p-6fw4-4hw8

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Withdrawn Advisory: Pulp Improper Path Parsing

Withdrawn Advisory

This advisory has been withdrawn because the package pulpcore deals with pulp 3 only. This advisory concerns pulp 2, which is not in a supported ecosystem.

Original Description

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.

Пакеты

Наименование

pulpcore

pip
Затронутые версииВерсия исправления

<= 2.16

Отсутствует

EPSS

Процентиль: 50%
0.00271
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.8
redhat
больше 7 лет назад

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.

CVSS3: 6.8
nvd
больше 7 лет назад

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.

EPSS

Процентиль: 50%
0.00271
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22