296,772
Total vulnerabilities in the database
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
| Software | From | Fixed in |
|---|---|---|
| pulpproject / pulp | 2.16.2 | 2.16.2.x |
| pulpproject / pulp | 2.16.1 | 2.16.1.x |
| pulpproject / pulp | 2.16.4 | 2.16.4.x |
| pulpproject / pulp | - | 2.16.0.x |