modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
References
Link | Resource |
---|---|
https://pagure.io/modulemd/issue/55 | Issue Tracking |
Configurations
Information
Published : 2019-01-10 13:29
Updated : 2023-02-28 18:22
NVD link : CVE-2017-1002157
Mitre link : CVE-2017-1002157
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
redhat
- modulemd