Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10917

Опубликовано: 14 авг. 2018
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.

A path traversal flaw was found in the ISO repository plugin for pulp. An attacker, with access to a repository feeding pulp can carefully craft his repository to overwrite arbitrary files owned by the Apache webserver.

Отчет

Red Hat Enterprise Virtualization Hypervisor includes only selected components of pulp, which are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Virtualization 4pulpNot affected
Red Hat Satellite 6.5 for RHEL 7ansiblerole-insights-clientFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7candlepinFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7createrepo_cFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foremanFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-bootloaders-redhatFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-discovery-imageFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-installerFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-proxyFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-selinuxFixedRHSA-2019:122214.05.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1598928pulp: Improper path parsing leads to overwriting of iso repositories

EPSS

Процентиль: 50%
0.00271
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
больше 7 лет назад

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.

CVSS3: 6.5
github
больше 3 лет назад

Withdrawn Advisory: Pulp Improper Path Parsing

EPSS

Процентиль: 50%
0.00271
Низкий

6.8 Medium

CVSS3

Уязвимость CVE-2018-10917