Vulnerabilities
Vulnerable Software
Pulpproject:  >> Pulp  >> 2.13.1  Security Vulnerabilities
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
CVSS Score
6.8
EPSS Score
0.004
Published
2018-08-15
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
CVSS Score
5.5
EPSS Score
0.003
Published
2018-06-18


Contact Us

Shodan ® - All rights reserved