MEDIUM 6.5 PyPI
koji hub allows arbitrary upload destinations
GHSA-7498-c9fm-g64p · CVE-2019-17109 · PYSEC-2019-183
Published · Modified
Description
The way that the hub code validates upload paths allows for an attacker to choose an arbitrary destination for the uploaded file.
Uploading still requires login. However, an attacker with credentials could damage the integrity of the Koji system.
Workaround
There is no known workaround. All Koji admins are encouraged to update to a fixed version as soon as possible.
Fix
Koji versions 1.14.3, 1.15.3, 1.16.3, 1.17.1, and 1.18.1 all include patches to solve this vulnerability.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2019-17109
- WEB https://github.com/koji-project/koji/commit/91d6f0b607c7f5af666dfb56931f1db4e38c28a5
- WEB https://docs.pagure.org/koji/CVE-2019-17109
- PACKAGE https://github.com/koji-project/koji
- WEB https://github.com/koji-project/koji/blob/d0507c4d2d2269daa984db642e3bd957dff18948/docs/source/CVEs/CVE-2019-17109.rst
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/koji/PYSEC-2019-183.yaml
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BGUXMZIAQFFNNQ7PEFDAYQCXXKJR76U
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PSCCFHLNVFLDPC7DB4UJGXD6ZWBSY57
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DEQYYGWLJBQQVTAC7E7XSDGVF27NPMPB
- WEB https://pagure.io/koji/commits/master
- WEB https://pagure.io/koji/issue/1634
- WEB https://pagure.io/koji/pull-request/1686
- WEB http://www.openwall.com/lists/oss-security/2019/10/09/5
Ready to move
Start Securing
Free, no credit card | First findings in minutes