CVE-2018-10917: Pulpproject Pulp
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
Affected products
- Pulpproject Pulp: up to and including 2.16.0; version 2.16.1 only; version 2.16.2 only; version 2.16.4 only
Published 2018-08-15. Last modified 2026-06-17.