GHSA-6mww-xvh7-fq4f

Suggest an improvement
Source
https://github.com/advisories/GHSA-6mww-xvh7-fq4f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-6mww-xvh7-fq4f/GHSA-6mww-xvh7-fq4f.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6mww-xvh7-fq4f
Aliases
Published
2018-07-12T20:29:40Z
Modified
2024-09-27T19:46:21.411135Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Koji hub call does not perform correct access checks
Details

Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1.

Database specific
{
    "nvd_published_at": "2018-04-04T20:29:00Z",
    "cwe_ids": [
        "CWE-732"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:19:49Z"
}
References

Affected packages

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.15
Fixed
1.15.1

Affected versions

1.*

1.15
1.15.0

Ecosystem specific

{
    "affected_functions": [
        "koji.auth.Session.__init__"
    ]
}

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.14
Fixed
1.14.1

Affected versions

1.*

1.14

Ecosystem specific

{
    "affected_functions": [
        "koji.auth.Session.__init__"
    ]
}

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.13
Fixed
1.13.1

Affected versions

1.*

1.13

Ecosystem specific

{
    "affected_functions": [
        "koji.auth.Session.__init__"
    ]
}

PyPI / koji

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.12
Fixed
1.12.1

Affected versions

1.*

1.12

Ecosystem specific

{
    "affected_functions": [
        "koji.auth.Session.__init__"
    ]
}