GHSA-7498-c9fm-g64p

Suggest an improvement
Source
https://github.com/advisories/GHSA-7498-c9fm-g64p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7498-c9fm-g64p/GHSA-7498-c9fm-g64p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7498-c9fm-g64p
Aliases
Published
2022-05-24T16:58:31Z
Modified
2024-09-27T18:35:02.936724Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
koji hub allows arbitrary upload destinations
Details

The way that the hub code validates upload paths allows for an attacker to choose an arbitrary destination for the uploaded file. Uploading still requires login. However, an attacker with credentials could damage the integrity of the Koji system.

Workaround

There is no known workaround. All Koji admins are encouraged to update to a fixed version as soon as possible.

Fix

Koji versions 1.14.3, 1.15.3, 1.16.3, 1.17.1, and 1.18.1 all include patches to solve this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "github_reviewed": true,
    "nvd_published_at": "2019-10-09T22:15:00Z",
    "severity": "HIGH",
    "github_reviewed_at": "2024-04-29T09:53:43Z"
}
References

Affected packages

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.14.0
Fixed
1.14.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7498-c9fm-g64p/GHSA-7498-c9fm-g64p.json"

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.15.0
Fixed
1.15.3

Affected versions

1.*
1.15.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7498-c9fm-g64p/GHSA-7498-c9fm-g64p.json"

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.16.0
Fixed
1.16.3

Affected versions

1.*
1.16.0
1.16.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7498-c9fm-g64p/GHSA-7498-c9fm-g64p.json"

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.17.0
Fixed
1.17.1

Affected versions

1.*
1.17.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7498-c9fm-g64p/GHSA-7498-c9fm-g64p.json"

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.18.0
Fixed
1.18.1

Affected versions

1.*
1.18.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7498-c9fm-g64p/GHSA-7498-c9fm-g64p.json"