Pulp Project Pulp 2.16.0

CPE Details

Pulp Project Pulp 2.16.0
2.16.0
2018-11-08
16h11 +00:00
2018-11-08
16h11 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:pulpproject:pulp:2.16.0:*:*:*:*:*:*:*

Informations

Vendor

pulpproject

Product

pulp

Version

2.16.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-10917 2018-08-15 15h00 +00:00 pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
6.8
Medium
CVE-2018-1090 2018-06-18 12h00 +00:00 In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
7.5
High