Vulnerabilities > Koji Project

DATE CVE VULNERABILITY TITLE RISK
2019-10-09 CVE-2019-17109 Path Traversal vulnerability in Koji Project Koji
Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.
network
low complexity
koji-project CWE-22
6.5
2018-04-04 CVE-2018-1002150 Incorrect Permission Assignment for Critical Resource vulnerability in Koji Project Koji
Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access.
network
low complexity
koji-project CWE-732
critical
9.1
2017-10-06 CVE-2017-1002153 Improper Input Validation vulnerability in Koji Project Koji 1.13.0
Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
network
low complexity
koji-project CWE-20
7.5