{"id":"GHSA-574p-6fw4-4hw8","summary":"Withdrawn Advisory: Pulp Improper Path Parsing","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because the package [pulpcore](https://pypi.org/project/pulpcore/) deals with pulp 3 only. This advisory concerns [pulp 2](https://github.com/pulp/pulp), which is not in a [supported ecosystem](https://github.com/github/advisory-database/blob/main/README.md#supported-ecosystems).\n\n## Original Description\npulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.","aliases":["CVE-2018-10917"],"modified":"2026-09-10T03:49:30.678732294Z","published":"2022-05-13T01:48:57Z","withdrawn":"2023-10-09T00:43:19Z","database_specific":{"nvd_published_at":"2018-08-15T17:29:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-07-21T22:25:33Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-10917"},{"type":"WEB","url":"https://access.redhat.com/errata/RHEA-2019:1283"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:1222"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2018-10917"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1598928"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10917"}],"affected":[{"package":{"name":"pulpcore","ecosystem":"PyPI","purl":"pkg:pypi/pulpcore"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-574p-6fw4-4hw8/GHSA-574p-6fw4-4hw8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}