High severity7.5NVD Advisory· Published Oct 6, 2017· Updated May 13, 2026
CVE-2017-1002153
CVE-2017-1002153
Description
Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kojiPyPI | < 1.15.0 | 1.15.0 |
Affected products
2- cpe:2.3:a:koji_project:koji:1.13.0:*:*:*:*:*:*:*
- Koji Project/Kojiv5Range: 1.13.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- pagure.io/koji/issue/563nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-vwp5-w4rq-g4ccghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-1002153ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/koji/PYSEC-2017-144.yamlghsaWEB
News mentions
0No linked articles in our index yet.