ZeroHour

CVE-2018-10917

CVSS 3.0
6.5 medium
EPSS
1%p63
Published
()
Modified
Description

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.

Vendors
pulpproject
Products
pulp
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.