Sceawere

Vulnerability Detail

CVE-2026-103870UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

pulp-rpm Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5
Creation Date
4h ago
Vendor
Red Hat
Product
Red Hat Satellite 6
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.0",
  "pubDate": "2026-10-07T06:16:35.373Z",
  "pubdate": "2026-10-07T06:16:35.373Z",
  "executiveSummary": "A path traversal vulnerability exists in pulp-rpm related to the handling of .treeinfo files during the publication of a distribution tree.\nThe vulnerability occurs because the application uses unsanitized 'addon' and 'variant' identifiers from the .treeinfo file as directory names when creating the distribution tree structure.\nAn authenticated user with the ability to sync or upload a distribution tree can exploit this flaw to perform unauthorized file system operations by traversing outside of the designated task work area.\nThe exploitation allows the Pulp worker user to write repository metadata and package files to arbitrary locations on the file system, constrained by the permissions of the user running the Pulp worker process.\nWhile the vulnerability does not directly disclose data or cause a denial-of-service condition, it poses a significant risk by allowing for unauthorized file placement, which could potentially lead to further system compromise depending on the target directory.\nThe vulnerability is restricted to environments where a user has permission to manage distribution trees, and it does not allow the replacement of existing files or directories.",
  "technicalDetails": "The root cause of this vulnerability is improper validation and sanitization of input data retrieved from .treeinfo files during the pulp-rpm distribution tree publication process.\nSpecifically, the application takes the 'addon' and 'variant' identifiers from the .treeinfo file and directly uses these strings as components of the directory path where the distribution tree is published.\nBecause these identifiers are not checked for directory traversal sequences (such as '../'), an attacker can provide a specially crafted .treeinfo file containing path traversal sequences within the 'addon' or 'variant' fields.\nThe attack flow proceeds as follows: First, the attacker initiates a sync or upload operation for a malicious distribution tree. This tree includes a .treeinfo file where the 'addon' or 'variant' ID is configured with sequences like '../../../../tmp/malicious_dir'. When the pulp-rpm worker processes this tree for publication, it interprets these sequences as navigation instructions to move out of the expected base working directory. Consequently, the worker process creates the attacker-specified directory path outside of the intended scope and writes the repository metadata and package files into that location.\nThe exploitation is constrained by the privileges of the Pulp worker user; the worker can only create directories and write files in locations where the worker user has write permissions.\nImportantly, the vulnerability logic explicitly prevents the overwrite of existing files or directories, meaning the attacker cannot disrupt existing system services or modify existing critical configuration files directly.\nThe post-exploitation impact is primarily the unauthorized placement of files on the system, which may be leveraged to facilitate secondary attacks or as part of a larger exploitation chain, depending on what further mechanisms might interact with the newly created directory and files.\nThe vulnerability resides within the pulp-rpm component responsible for processing and publishing distribution trees."
}
CVE-2026-103870: pulp-rpm Path Traversal Vulnerability (MEDIUM Severity, CVSS: 5.0) | Sceawere