VYPR

PyPI package

pulpcore

pkg:pypi/pulpcore

Vulnerabilities (2)

  • CVE-2024-7143Aug 7, 2024
    affected <= 3.56.0

    A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the

  • CVE-2018-10917Aug 15, 2018
    affected <= 2.16

    pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.