Red Hat Subscription Asset Manager

CPE Details

Red Hat Subscription Asset Manager
-
2019-12-06
17h57 +00:00
2019-12-06
17h57 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:subscription_asset_manager:-:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

subscription_asset_manager

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2012-6685 2020-02-19 13h41 +00:00 Nokogiri before 1.5.4 is vulnerable to XXE attacks
7.5
High
CVE-2013-6461 2019-11-05 13h07 +00:00 Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
6.5
Medium
CVE-2013-6460 2019-11-05 13h02 +00:00 Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
6.5
Medium
CVE-2014-0130 2014-05-07 10h00 +00:00 Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
7.5
High
CVE-2012-6119 2013-04-02 22h00 +00:00 Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
2.1
CVE-2013-1823 2013-04-02 22h00 +00:00 Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
4.3