PT-2019-14949 · Red Hat · Koji

Published

2019-10-09

·

Updated

2022-05-24

·

CVE-2019-17109

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Koji versions 1.14.0 through 1.18.0
Description The issue allows remote Directory Traversal, resulting in Privilege Escalation. It is caused by the way the hub code validates upload paths, enabling an attacker to choose an arbitrary destination for the uploaded file. However, uploading still requires login credentials. An attacker with credentials could potentially damage the integrity of the Koji system.
Recommendations For versions 1.14.0 through 1.14.2, update to version 1.14.3. For versions 1.15.0 through 1.15.2, update to version 1.15.3. For versions 1.16.0 through 1.16.2, update to version 1.16.3. For versions 1.17.0, update to version 1.17.1. For versions 1.18.0, update to version 1.18.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17109
GHSA-7498-C9FM-G64P
MGASA-2021-0147
PYSEC-2019-183

Affected Products

Koji