Vulnerability Description
Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Koji Project | Koji | 1.12.0 |
Related Weaknesses (CWE)
References
- https://docs.pagure.org/koji/CVE-2018-1002150/MitigationThird Party Advisory
- https://pagure.io/koji/issue/850Third Party Advisory
- https://docs.pagure.org/koji/CVE-2018-1002150/MitigationThird Party Advisory
- https://pagure.io/koji/issue/850Third Party Advisory
FAQ
What is CVE-2018-1002150?
CVE-2018-1002150 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13...
How severe is CVE-2018-1002150?
CVE-2018-1002150 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-1002150?
Check the references section above for vendor advisories and patch information. Affected products include: Koji Project Koji.