Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
References
| Link | Resource |
|---|---|
| https://pagure.io/koji/issue/563 | Patch |
Configurations
Information
Published : 2017-10-06 17:29
Updated : 2019-10-09 23:21
NVD link : CVE-2017-1002153
Mitre link : CVE-2017-1002153
JSON object : View
Products Affected
koji_project
- koji
CWE
CWE-20
Improper Input Validation
