CVE-2018-10917: Path Traversal
Withdrawn Advisory This advisory has been withdrawn because the package pulpcore deals with pulp 3 only. This advisory concerns pulp 2, which is not in a supported ecosystem.
Original Description pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
Other sources
A flaw was found in pulp 2.16.x and possibly older. A malicious user or a malicious iso feed repository can write to locations accessible to the ‘apache’ user. This may lead to overwrite of published content on other iso repositories.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2018-10917.
What is the severity of CVE-2018-10917?
The severity of CVE-2018-10917 is medium with a CVSS score of 6.5.
What software is affected by CVE-2018-10917?
The software affected by CVE-2018-10917 includes pulpcore versions 2.16.0, 2.16.1, and 2.16.2.
How can I fix CVE-2018-10917?
To fix CVE-2018-10917, it is recommended to update to a version of pulpcore that is not affected by the vulnerability.
Where can I find more information about CVE-2018-10917?
More information about CVE-2018-10917 can be found in the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1616079), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2019:1222), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1598928).