Pulp Project Pulp 2.8.4

CPE Details

Pulp Project Pulp 2.8.4
2.8.4
2019-10-16
11h00 +00:00
2019-10-16
11h00 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:pulpproject:pulp:2.8.4:*:*:*:*:*:*:*

Informations

Vendor

pulpproject

Product

pulp

Version

2.8.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-10917 2018-08-15 15h00 +00:00 pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
6.8
Medium
CVE-2018-1090 2018-06-18 12h00 +00:00 In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
7.5
High
CVE-2016-3704 2017-06-13 15h00 +00:00 Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
7.5
High
CVE-2016-3696 2017-06-13 14h00 +00:00 The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
5.5
Medium