Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
References
Link | Resource |
---|---|
https://pagure.io/koji/issue/563 | Issue Tracking Patch |
Configurations
Information
Published : 2017-10-06 10:29
Updated : 2023-02-28 18:13
NVD link : CVE-2017-1002153
Mitre link : CVE-2017-1002153
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
koji_project
- koji