GHSA-574p-6fw4-4hw8
Dashboard / Vulnerabilities / GHSA-574p-6fw4-4hw8
Summary: Withdrawn Advisory: Pulp Improper Path Parsing
Details: ## Withdrawn Advisory This advisory has been withdrawn because the package [pulpcore](https://pypi.org/project/pulpcore/) deals with pulp 3 only. This advisory concerns [pulp 2](https://github.com/pulp/pulp), which is not in a [supported ecosystem](https://github.com/github/advisory-database/blob/main/README.md#supported-ecosystems). ## Original Description pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-10917, https://access.redhat.com/errata/RHEA-2019:1283, https://access.redhat.com/errata/RHSA-2019:1222, https://access.redhat.com/security/cve/CVE-2018-10917, https://bugzilla.redhat.com/show_bug.cgi?id=1598928, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10917
Affected packages
Package
Name: pulpcore
Purl: pkg:pypi/pulpcore
Affected ranges
Type: ECOSYSTEM
Events:
