Tag
An authenticated path traversal vulnerability in the pulpcore content upload API allows users to bypass file scheme validation and read arbitrary files on the server process by manipulating the file_url parameter.