Directory Traversal Vulnerability in Pulp RPM by Red Hat
CVE-2026-103870
5MEDIUM
What is CVE-2026-103870?
A directory traversal vulnerability exists in Pulp RPM when publishing a distribution tree. This flaw permits users with sync or upload capabilities to manipulate the publishing process, allowing the creation of directories outside the intended work area. As a result, repository metadata and packages can be written to unintended locations by the Pulp worker user. However, this flaw does not overwrite existing files or directories, nor does it compromise any data.
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Daoqing Yu for reporting this issue.