Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 PyPI

koji hub allows arbitrary upload destinations

GHSA-7498-c9fm-g64p · CVE-2019-17109 · PYSEC-2019-183

Published · Modified

Description

The way that the hub code validates upload paths allows for an attacker to choose an arbitrary destination for the uploaded file.
Uploading still requires login. However, an attacker with credentials could damage the integrity of the Koji system.

Workaround

There is no known workaround. All Koji admins are encouraged to update to a fixed version as soon as possible.

Fix

Koji versions 1.14.3, 1.15.3, 1.16.3, 1.17.1, and 1.18.1 all include patches to solve this vulnerability.

Ready to move

Start Securing

Free, no credit card | First findings in minutes