Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pulp HIGH 8.3
CVE-2024-7143

A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses th…

Mitigation only
Fix from $1,950 2024-08-07
Pulp MEDIUM 6.5
CVE-2018-10917

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations …

Fix: after 2.16.0
Fix from $1,600 2018-08-15
Qpid HIGH 7.2
CVE-2015-5164

The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access o…

Mitigation only
Fix from $1,950 2017-10-18
Pulp HIGH 8.1
CVE-2015-5263

pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registra…

Patch available
Fix from $1,950 2017-09-25
Pulp HIGH 7.5
CVE-2016-3112

client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows r…

Fix: after 2.8.2-1
Fix from $1,950 2017-06-08
Pulp HIGH 7.1
CVE-2016-3108

The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.

Fix: after 2.8.2-1
Fix from $1,950 2017-06-08
Pulp MEDIUM 5.5
CVE-2016-3107

The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, w…

Fix: after 2.8.2-1
Fix from $1,600 2017-06-08
Pulp MEDIUM 5.5
CVE-2016-3111

pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers…

Fix: after 2.8.2-1
Fix from $1,600 2017-06-08
Pulp MEDIUM 5.3
CVE-2016-3106

Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.

Patch available
Fix from $1,600 2017-04-13
Pulp HIGH 7.5
CVE-2013-7450

Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.

Fix: after 2.2.1-1
Fix from $1,950 2017-04-03