{"id":"CVE-2019-17109","aliases":["PYSEC-2019-183"],"url":"https://o3.security/vulnerability/CVE-2019-17109","summary":"koji hub allows arbitrary upload destinations","details":"The way that the hub code validates upload paths allows for an attacker to choose an arbitrary destination for the uploaded file.\nUploading still requires login. However, an attacker with credentials could damage the integrity of the Koji system.\n\n### Workaround\nThere is no known workaround. All Koji admins are encouraged to update to a fixed version as soon as possible.\n\n### Fix\nKoji versions 1.14.3, 1.15.3, 1.16.3, 1.17.1, and 1.18.1 all include patches to solve this vulnerability.\n\n","published":"2022-05-24T16:58:31Z","modified":"2024-09-27T18:35:02.936724Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.14.3"},{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.15.3"},{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.16.3"},{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.17.1"},{"ecosystem":"PyPI","name":"koji","fixedVersion":"1.18.1"}],"fix":{"url":"https://github.com/koji-project/koji/commit/91d6f0b607c7f5af666dfb56931f1db4e38c28a5","label":"koji-project/koji@91d6f0b"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-17109"},{"type":"WEB","url":"https://github.com/koji-project/koji/commit/91d6f0b607c7f5af666dfb56931f1db4e38c28a5"},{"type":"WEB","url":"https://docs.pagure.org/koji/CVE-2019-17109"},{"type":"PACKAGE","url":"https://github.com/koji-project/koji"},{"type":"WEB","url":"https://github.com/koji-project/koji/blob/d0507c4d2d2269daa984db642e3bd957dff18948/docs/source/CVEs/CVE-2019-17109.rst"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/koji/PYSEC-2019-183.yaml"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BGUXMZIAQFFNNQ7PEFDAYQCXXKJR76U"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PSCCFHLNVFLDPC7DB4UJGXD6ZWBSY57"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DEQYYGWLJBQQVTAC7E7XSDGVF27NPMPB"},{"type":"WEB","url":"https://pagure.io/koji/commits/master"},{"type":"WEB","url":"https://pagure.io/koji/issue/1634"},{"type":"WEB","url":"https://pagure.io/koji/pull-request/1686"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2019/10/09/5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-09-27T18:35:02.936724Z"}}