-
CVSS Score
-The vulnerability stems from two key points: 1) The perform_task function in _util.py explicitly uses get_users_with_perms().first() to determine the task's user context, which matches the described 'oldest user' flaw. 2) The AutoAddObjPermsMixin (implied in role_util.py) inherits this incorrect user context when assigning permissions. High confidence for perform_task is justified by the direct code reference in the advisory (line 108 of _util.py). Medium confidence for the mixin method stems from its described role in the vulnerability, though exact code isn't shown.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| pulpcore | pip | <= 3.56.0 |
A Semantic Attack on Google Gemini - Read the Latest Research