MGASA-2019-0144
Dashboard / Vulnerabilities / MGASA-2019-0144
Summary: Updated koji packages fix security vulnerability
Details: Multiple xmlrpc call handlers in Koji’s hub code contain SQL injection bugs. By passing carefully constructed arguments to these calls, an unauthenticated user can issue arbitrary SQL commands to Koji’s database. This gives the attacker broad ability to manipulate or destroy data (CVE-2018-1002161).
References: https://advisories.mageia.org/MGASA-2019-0144.html, https://bugs.mageia.org/show_bug.cgi?id=24421, https://docs.pagure.org/koji/CVE-2018-1002161/, https://lists.fedoraproject.org/archives/list/[email protected]/thread/ZK4UFB6Q4EDKJYDCXJ7R43EBRSWBS3SR/
Affected packages
Package
Name: koji
Purl: pkg:rpm/mageia/koji?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
