GHSA-7498-c9fm-g64p
Dashboard / Vulnerabilities / GHSA-7498-c9fm-g64p
GHSA-7498-c9fm-g64p
Summary: koji hub allows arbitrary upload destinations
Details: The way that the hub code validates upload paths allows for an attacker to choose an arbitrary destination for the uploaded file. Uploading still requires login. However, an attacker with credentials could damage the integrity of the Koji system. ### Workaround There is no known workaround. All Koji admins are encouraged to update to a fixed version as soon as possible. ### Fix Koji versions 1.14.3, 1.15.3, 1.16.3, 1.17.1, and 1.18.1 all include patches to solve this vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-17109, https://github.com/koji-project/koji/commit/91d6f0b607c7f5af666dfb56931f1db4e38c28a5, https://docs.pagure.org/koji/CVE-2019-17109, https://github.com/koji-project/koji, https://github.com/koji-project/koji/blob/d0507c4d2d2269daa984db642e3bd957dff18948/docs/source/CVEs/CVE-2019-17109.rst, https://github.com/pypa/advisory-database/tree/main/vulns/koji/PYSEC-2019-183.yaml, https://lists.fedoraproject.org/archives/list/[email protected]/message/4BGUXMZIAQFFNNQ7PEFDAYQCXXKJR76U, https://lists.fedoraproject.org/archives/list/[email protected]/message/7PSCCFHLNVFLDPC7DB4UJGXD6ZWBSY57, https://lists.fedoraproject.org/archives/list/[email protected]/message/DEQYYGWLJBQQVTAC7E7XSDGVF27NPMPB, https://pagure.io/koji/commits/master, https://pagure.io/koji/issue/1634, https://pagure.io/koji/pull-request/1686, http://www.openwall.com/lists/oss-security/2019/10/09/5
Affected packages
Package
Name: koji
Purl: pkg:pypi/koji
Affected ranges
Type: ECOSYSTEM
Events:
