Bug 1598068

Summary: security issue: reposync follows remotely-provided relative paths including ../
Product: [Fedora] Fedora Reporter: Marek Blaha <mblaha>
Component: dnf-plugins-coreAssignee: Marek Blaha <mblaha>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 29CC: dmach, elfchief-redhatbugs, emrakova, ksrot, mdomonko, packaging-team-maint, qe-baseos-security, rpm-software-management, rschiron, vmukhame
Target Milestone: ---Keywords: Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1552328 Environment:
Last Closed: 2019-04-04 11:44:32 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1552328, 1600221    
Bug Blocks:    

Comment 1 Jan Kurik 2018-08-14 10:53:26 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 29 development cycle.
Changing version to '29'.