Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
References
Link | Resource |
---|---|
https://pagure.io/koji/issue/563 | Issue Tracking Patch |
Configurations
History
01 Mar 2023, 02:13
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://pagure.io/koji/issue/563 - Issue Tracking, Patch |
Information
Published : 2017-10-06 17:29
Updated : 2024-02-04 19:29
NVD link : CVE-2017-1002153
Mitre link : CVE-2017-1002153
CVE.ORG link : CVE-2017-1002153
JSON object : View
Products Affected
koji_project
- koji
CWE
CWE-20
Improper Input Validation