Path Traversal Vulnerability in Pulpcore by Red Hat
⚠️ CVE-Referenzen:
CVE-2026-12701
Red Hat - Red Hat Ansible Automation Platform 2 - CRITICAL - CVE-2026-12701.
A path traversal vulnerability exists in Pulpcore, specifically in the relative_path_validator function. This function incorrectly validates content paths by only ensuring they do not start with a '/' character, thus inadequately addressing directory traversal sequences such as '../'. With this flaw, an authenticated administrator can exploit relative_path variables to incorporate traversal sequences that can navigate outside the intended export directory during FilesystemExport operations. Since the uploaded file content can also be controlled by the user, this vulnerability permits arbitrary file writes to any writable location by the Pulp service user, posing a significant risk of service compromise or enabling further system exploitation.
Quelle: securityvulnerability.io