REDHAT-BUG-2490703: Path Traversal

Published Jun 19, 2026
·
Updated

A path traversal vulnerability was found in pulpcore's relativepathvalidator (pulpcore/app/serializers/fields.py). The validator only checks os.path.isabs() to block paths starting with "/", but does not block "../" directory traversal sequences anywhere in the path.

When a user creates content via POST /api/v3/content/file/files/ with a crafted relativepath (e.g., "looking/normal/../../../../etc/cron.d/backdoor"), the value passes validation and is stored in ContentArtifact.relativepath. During FilesystemExport (pulpcore/app/tasks/export.py), os.path.join(path, relativepath) resolves outside the export directory, and the raw artifact content (fully attacker-controlled) is written to the escaped path.

The process runs as the "pulp" system user. File permission bits cannot be set by the attacker. FilesystemExport is only accessible to admin-level users (SSL cert auth in Satellite, admin role in RBAC deployments).

Affected: pulpcore (all versions through current HEAD 3.110.0.dev) Fix: Not yet available (coordinating with upstream) Reporter: Martin Brodeur (independent security researcher) PSIRT Ticket: PSIRTSUPT-7617

Affected Software

1 affected component
Pulp Pulpcore<=3.110.0.dev

Event History

Jun 19, 2026
Data Sourced
via Red Hat·09:54 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2490703?

The severity of REDHAT-BUG-2490703 is rated as high with a score of 7.

2

How do I fix REDHAT-BUG-2490703?

To fix REDHAT-BUG-2490703, update to the latest version of Pulp Pulpcore where the issue has been resolved.

3

What type of vulnerability is REDHAT-BUG-2490703?

REDHAT-BUG-2490703 is a path traversal vulnerability.

4

What impact does REDHAT-BUG-2490703 have on Pulp Pulpcore security?

The impact of REDHAT-BUG-2490703 can allow an attacker to access unauthorized files due to improper input validation.

5

When was REDHAT-BUG-2490703 published?

REDHAT-BUG-2490703 was published on June 19, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203