Описание
Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
Ссылки
- Issue TrackingPatch
- Issue TrackingPatch
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:koji_project:koji:1.13.0:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.0032
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-20
CWE-20
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 8 лет назад
Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
CVSS3: 7.5
debian
больше 8 лет назад
Koji 1.13.0 does not properly validate SCM paths, allowing an attacker ...
EPSS
Процентиль: 55%
0.0032
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-20
CWE-20