modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
References
| Link | Resource |
|---|---|
| https://pagure.io/modulemd/issue/55 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2019-01-10 21:29
Updated : 2019-10-09 23:21
NVD link : CVE-2017-1002157
Mitre link : CVE-2017-1002157
JSON object : View
Products Affected
redhat
- modulemd
CWE
CWE-20
Improper Input Validation
