Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1079
HistoryApr 09, 2018 - 11:49 a.m.

CVE-2018-1079

2018-04-0911:49:00
redhat.com
access.redhat.com
12

0.001 Low

EPSS

Percentile

29.7%

It was found that the REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth directory exists, an authenticated attacker with write permissions could create or overwrite arbitrary files with arbitrary data outside of the /etc/booth directory, in the context of the pcsd process.