Koji is a build and release-management system widely used in open-source distribution pipelines, particularly within the Red Hat and Fedora ecosystems, where its role in artifact provenance and integrity makes even modest flaws operationally significant. The observed vulnerability profile centers on input-validation issues, path-traversal weaknesses, and improper permission assignment on critical resources—flaws that reflect the system's responsibility for authenticating build requests, managing filesystem boundaries, and controlling access to build artifacts and metadata. Current severity, exploitation activity, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Koji Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1002150CRITICAL Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in v | Apr 4, 2018 | 9.1 | 28 | NO | NO |
CVE-2017-1002153HIGH Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission. | Oct 6, 2017 | 7.5 | 24 | NO | NO |
CVE-2019-17109MEDIUM Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation. | Oct 9, 2019 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Koji Project.
Media articles that mention a CVE ID that affects a product developed by Koji Project — matched by CVE ID, not by vendor name.