CVE-2018-10917

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
Configurations

Configuration 1

cpe:2.3:a:pulpproject:pulp:2.16.2:*:*:*:*:*:*:*
cpe:2.3:a:pulpproject:pulp:2.16.1:*:*:*:*:*:*:*
cpe:2.3:a:pulpproject:pulp:2.16.4:*:*:*:*:*:*:*
cpe:2.3:a:pulpproject:pulp:*:*:*:*:*:*:*:*

Information

Published : 2018-08-15 05:29

Updated : 2023-02-12 10:15


NVD link : CVE-2018-10917

Mitre link : CVE-2018-10917

Products Affected
No products.
CWE