{"id":"CVE-2018-1002150","aliases":["PYSEC-2018-86"],"url":"https://o3.security/vulnerability/CVE-2018-1002150","summary":"Koji hub call does not perform correct access checks","details":"Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1.","published":"2018-07-12T20:29:40Z","modified":"2025-02-18T05:27:38.515234Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.15.1"},{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.14.1"},{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.13.1"},{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.12.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1002150"},{"type":"WEB","url":"https://docs.pagure.org/koji/CVE-2018-1002150"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6mww-xvh7-fq4f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/koji/PYSEC-2018-86.yaml"},{"type":"PACKAGE","url":"https://pagure.io/koji"},{"type":"WEB","url":"https://pagure.io/koji/c/ab1ade7"},{"type":"WEB","url":"https://pagure.io/koji/issue/850"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-18T05:27:38.515234Z"}}