CVE-2019-17109

MEDIUM6.5EPSS 0.56%

koji hub allows arbitrary upload destinations

發布日:2022/5/24修改日:2024/9/27
也稱為:GHSA-7498-c9fm-g64pPYSEC-2019-183

描述

The way that the hub code validates upload paths allows for an attacker to choose an arbitrary destination for the uploaded file. Uploading still requires login. However, an attacker with credentials could damage the integrity of the Koji system. ### Workaround There is no known workaround. All Koji admins are encouraged to update to a fixed version as soon as possible. ### Fix Koji versions 1.14.3, 1.15.3, 1.16.3, 1.17.1, and 1.18.1 all include patches to solve this vulnerability.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

參考連結(17)