pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| pulpcore(PyPI) | 0 | N/A | N/A |
CVSS Metrics