Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
{
"github_reviewed": true,
"github_reviewed_at": "2024-11-22T20:19:16Z",
"severity": "HIGH",
"nvd_published_at": "2017-10-06T17:29:00Z",
"cwe_ids": [
"CWE-20"
]
}