The host.distRepoMove hub call does not perform the correct access checks. This bug allows an attacker to manipulate the filesystem, potentially destroying data or exposing secrets.
host.distRepoMove
This issue has been assigned CVE-2018-1002150
You can read the full announcement here: https://docs.pagure.org/koji/CVE-2018-1002150/
Commit ab1ade75 fixes this issue
Metadata Update from @mikem: - Issue private status set to: False (was: True)
Metadata Update from @tkopecek: - Issue set to the milestone: 1.16
This issue has been migrated to Fedora Forge: https://forge.fedoraproject.org/koji/koji/issues/850
Please continue any further discussion there.