Withdrawn Advisory: Pulp Improper Path Parsing
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 9, 2023
Withdrawn
This advisory was withdrawn on Oct 9, 2023
Description
Published by the National Vulnerability Database
Aug 15, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 21, 2023
Withdrawn
Oct 9, 2023
Last updated
Oct 9, 2023
Withdrawn Advisory
This advisory has been withdrawn because the package pulpcore deals with pulp 3 only. This advisory concerns pulp 2, which is not in a supported ecosystem.
Original Description
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
References