CVE-2018-1002150: Koji Project Koji
Critical severity, CVSS 9.1. EPSS: 1.7% chance of exploitation in the next 30 days.
Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1.
Affected products
- Koji Project Koji: version 1.12.0 only; version 1.13.0 only; version 1.14.0 only; version 1.15.0 only
Published 2018-04-04. Last modified 2026-06-17.