Medium severity6.8NVD Advisory· Published Aug 15, 2018· Updated Jun 17, 2026
CVE-2018-10917
CVE-2018-10917
Description
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pulpcorePyPI | <= 2.16 | — |
Affected products
5cpe:2.3:a:pulpproject:pulp:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:pulpproject:pulp:*:*:*:*:*:*:*:*range: <=2.16.0
- cpe:2.3:a:pulpproject:pulp:2.16.1:*:*:*:*:*:*:*
- cpe:2.3:a:pulpproject:pulp:2.16.2:*:*:*:*:*:*:*
- cpe:2.3:a:pulpproject:pulp:2.16.4:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-574p-6fw4-4hw8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-10917ghsaADVISORY
- access.redhat.com/errata/RHEA-2019:1283ghsaWEB
- access.redhat.com/errata/RHSA-2019:1222nvdWEB
- access.redhat.com/security/cve/CVE-2018-10917ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
News mentions
0No linked articles in our index yet.