Directory Traversal Vulnerability in Pulp RPM by Red Hat
CVE-2026-103870

5MEDIUM

What is CVE-2026-103870?

A directory traversal vulnerability exists in Pulp RPM when publishing a distribution tree. This flaw permits users with sync or upload capabilities to manipulate the publishing process, allowing the creation of directories outside the intended work area. As a result, repository metadata and packages can be written to unintended locations by the Pulp worker user. However, this flaw does not overwrite existing files or directories, nor does it compromise any data.

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Daoqing Yu for reporting this issue.
.