CVE-2018-10917 – pulpcore
Package
Manager: pip
Name: pulpcore
Vulnerable Version: <0
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: N/A
EPSS: 0.00271 pctl0.50251
Details
Withdrawn Advisory: Pulp Improper Path Parsing ## Withdrawn Advisory This advisory has been withdrawn because the package [pulpcore](https://pypi.org/project/pulpcore/) deals with pulp 3 only. This advisory concerns [pulp 2](https://github.com/pulp/pulp), which is not in a [supported ecosystem](https://github.com/github/advisory-database/blob/main/README.md#supported-ecosystems). ## Original Description pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
Metadata
Created: 2022-05-13T01:48:57Z
Modified: 2023-10-09T00:43:19Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-574p-6fw4-4hw8/GHSA-574p-6fw4-4hw8.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-574p-6fw4-4hw8
Finding: N/A
Auto approve: 0