candlepinproject Candlepin

CPE Details

candlepinproject Candlepin
-
2020-04-22
14h13 +00:00
2020-04-22
14h13 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:candlepinproject:candlepin:-:*:*:*:*:*:*:*

Informations

Vendor

candlepinproject

Product

candlepin

Version

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-1832 2023-10-04 13h05 +00:00 An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
8.1
Haute
CVE-2015-5187 2017-07-25 16h00 +00:00 Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
6.5
Moyen
CVE-2012-6119 2013-04-02 22h00 +00:00 Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
2.1