Impact
When publishing a distribution tree, Pulp-rpm uses addon and variant IDs from the .treeinfo file as directory names. If an attacker crafts these IDs, the publish process can create a new directory outside the intended task work area and write repository metadata and packages there as the Pulp worker user. Existing files or directories are not overwritten, yet the flaw allows the creation of arbitrary files in privileged locations, which could be used to store malicious content or alter critical data. The vulnerability does not disclose data or stop the service, but it permits unauthorized file creation under elevated privileges.
Affected Systems
The flaw affects Red Hat Satellite 6, Red Hat Update Infrastructure 4 for Cloud Providers, and Red Hat Update Infrastructure 5. No specific version ranges are listed, but any deployment of these products that uses pulp-rpm for distribution tree publishing is potentially impacted.
Risk and Exploitability
The CVSS score of 5 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Attacks would require an actor with the ability to sync or upload a distribution tree to the system—typically a user with authorized repository management permissions. The likelihood of exploitation depends on the presence of such permissions and the usage of untrusted upstream sources. The official workaround states that syncing from trusted upstreams avoids a crafted .treeinfo file, but an account that can upload a tree directly can still supply the file. Until a patched version is released, the risk remains for administrators who grant sync or upload rights to users that are not fully trusted.
OpenCVE Enrichment