GHSA-7498-c9fm-g64p

    Dashboard / Vulnerabilities / GHSA-7498-c9fm-g64p

    GHSA-7498-c9fm-g64p

    Published: 24 May 2022Last Modified: 27 Sept 2024

    Summary: koji hub allows arbitrary upload destinations

    Details: The way that the hub code validates upload paths allows for an attacker to choose an arbitrary destination for the uploaded file. Uploading still requires login. However, an attacker with credentials could damage the integrity of the Koji system. ### Workaround There is no known workaround. All Koji admins are encouraged to update to a fixed version as soon as possible. ### Fix Koji versions 1.14.3, 1.15.3, 1.16.3, 1.17.1, and 1.18.1 all include patches to solve this vulnerability.

    Affected packages

    Package

    Name: koji

    Purl: pkg:pypi/koji

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.14.0
    Fixed -1.14.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7498-c9fm-g64p | CVE-DB