Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Koji blacklisted paths workaround

GHSA-vwp5-w4rq-g4cc · CVE-2017-1002153

Published · Modified

Description

Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.

Ready to move

Start Securing

Free, no credit card | First findings in minutes