Fedora has issued an advisory on October 25: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7PSCCFHLNVFLDPC7DB4UJGXD6ZWBSY57/ The issue is fixed upstream in 1.18.1. Mageia 7 is also affected.
Whiteboard: (none) => MGA7TOO
Status comment: (none) => Fixed upstream in 1.18.1
koji-1.23.0-1.mga8 uploaded for Cauldron by Neal.
Whiteboard: MGA7TOO => (none)Version: Cauldron => 7
I've uploaded a fixed version to updates-testing for Mageia 7. Suggested advisory: ======================== Updated koji packages fix security vulnerabilities: Koji through 1.17.0 allows remote Directory Traversal, with resultant Privilege Escalation. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17109 https://bugzilla.redhat.com/show_bug.cgi?id=1768882 ======================== Updated packages in core/updates_testing: ======================== koji-1.17.1-1.mga7 python3-koji-1.17.1-1.mga7 python3-koji-cli-plugins-1.17.1-1.mga7 koji-hub-1.17.1-1.mga7 koji-hub-plugins-1.17.1-1.mga7 koji-builder-1.17.1-1.mga7 koji-vm-1.17.1-1.mga7 koji-utils-1.17.1-1.mga7 koji-web-1.17.1-1.mga7 Source RPMs: koji-1.17.1-1.mga7.src.rpm
Assignee: ngompa13 => qa-bugsStatus comment: Fixed upstream in 1.18.1 => Fixed upstream in 1.17.1
Status comment: Fixed upstream in 1.17.1 => (none)
Searched Bugzilla for previous updates, and found Bug 24421, where koji had been OKed and validated based on a clean install over the old packages. I went to install all of the packages on a real hardware test install, but discovered that the total install, including dependencies, would involve 128 packages. Not wanting all those extra packages left after the test, I switched to a VirtualBox mga7-64 Plasma guest. No installation issues when installing the current mga7 koji and dependencies, and all packages listed in Comment 2 updated cleanly. Sending this one on its way. Validating. Advisory in Comment 2.
Keywords: (none) => validated_updateWhiteboard: (none) => MGA7-64-OKCC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0147.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED