pulpproject records
15 published records for vendor pulpproject.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 60%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-284 Improper Access Control2
- CWE-295 Improper Certificate Validation2
- CWE-256 Plaintext Storage of a Password1
- CWE-277 Insecure Inherited Permissions1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2024-7143No exploit | Pulpcore: rbac permissions incorrectly assigned in tasks that create objectspulpproject · pulp · CWE-277 | High8.3 | — | 0.6% | Aug 7, 2024 |
32Monitor | CVE-2015-5263No exploit | pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key uponpulpproject · pulp · CWE-295 | High8.1 | — | 0.9% | Sep 25, 2017 |
31Monitor | CVE-2016-3112No exploit | client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, whichpulpproject · pulp · CWE-284 | High7.5 | — | 2.2% | Jun 8, 2017 |
31Monitor | CVE-2016-3704No exploit | Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.fedoraproject · fedora · CWE-255 | High7.5 | — | 2.0% | Jun 13, 2017 |
30Monitor | CVE-2018-1090No exploit | In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with reapulpproject · pulp · CWE-200 | High7.5 | — | 1.3% | Jun 18, 2018 |
30Monitor | CVE-2013-7450No exploit | Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.pulpproject · pulp · CWE-295 | High7.5 | — | 0.9% | Apr 3, 2017 |
29Monitor | CVE-2015-5164No exploit | The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrativepulpproject · qpid · CWE-502 | High7.2 | — | 4.0% | Oct 18, 2017 |
28Monitor | CVE-2016-3108No exploit | The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attpulpproject · pulp · CWE-59 | High7.1 | — | 0.3% | Jun 8, 2017 |
26Monitor | CVE-2018-10917No exploit | pulp 2.16.x and possibly older is vulnerable to an improper path parsing.pulpproject · pulp · CWE-22 | Medium6.5 | — | 1.1% | Aug 15, 2018 |
22Monitor | CVE-2016-3111No exploit | pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp pulpproject · pulp · CWE-200 | Medium5.5 | — | 0.4% | Jun 8, 2017 |
22Monitor | CVE-2016-3696No exploit | The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.fedoraproject · fedora · CWE-200 | Medium5.5 | — | 0.4% | Jun 13, 2017 |
22Monitor | CVE-2016-3095No exploit | server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.fedoraproject · fedora · CWE-200 | Medium5.5 | — | 0.3% | Jun 8, 2017 |
22Monitor | CVE-2022-3644No exploit | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write modpulpproject · pulp ansible · CWE-256 | Medium5.5 | — | 0.3% | Oct 25, 2022 |
22Monitor | CVE-2016-3107No exploit | The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" dirpulpproject · pulp · CWE-284 | Medium5.5 | — | 0.2% | Jun 8, 2017 |
21Monitor | CVE-2016-3106No exploit | Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.pulpproject · pulp · CWE-362 | Medium5.3 | — | 0.9% | Apr 13, 2017 |
- CVE-2024-714333Monitor
Pulpcore: rbac permissions incorrectly assigned in tasks that create objects
HighCVSS 8.3No exploitEPSS 1%pulpproject · pulpAug 7, 2024
- CVE-2015-526332Monitor
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon
HighCVSS 8.1No exploitEPSS 1%pulpproject · pulpSep 25, 2017
- CVE-2016-311231Monitor
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which
HighCVSS 7.5No exploitEPSS 2%pulpproject · pulpJun 8, 2017
- CVE-2016-370431Monitor
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
HighCVSS 7.5No exploitEPSS 2%fedoraproject · fedoraJun 13, 2017
- CVE-2018-109030Monitor
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with rea
HighCVSS 7.5No exploitEPSS 1%pulpproject · pulpJun 18, 2018
- CVE-2013-745030Monitor
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
HighCVSS 7.5No exploitEPSS 1%pulpproject · pulpApr 3, 2017
- CVE-2015-516429Monitor
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative
HighCVSS 7.2No exploitEPSS 4%pulpproject · qpidOct 18, 2017
- CVE-2016-310828Monitor
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink att
HighCVSS 7.1No exploitEPSS 0%pulpproject · pulpJun 8, 2017
- CVE-2018-1091726Monitor
pulp 2.16.x and possibly older is vulnerable to an improper path parsing.
MediumCVSS 6.5No exploitEPSS 1%pulpproject · pulpAug 15, 2018
- CVE-2016-311122Monitor
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp
MediumCVSS 5.5No exploitEPSS 0%pulpproject · pulpJun 8, 2017
- CVE-2016-369622Monitor
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
MediumCVSS 5.5No exploitEPSS 0%fedoraproject · fedoraJun 13, 2017
- CVE-2016-309522Monitor
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
MediumCVSS 5.5No exploitEPSS 0%fedoraproject · fedoraJun 8, 2017
- CVE-2022-364422Monitor
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mod
MediumCVSS 5.5No exploitEPSS 0%pulpproject · pulp ansibleOct 25, 2022
- CVE-2016-310722Monitor
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" dir
MediumCVSS 5.5No exploitEPSS 0%pulpproject · pulpJun 8, 2017
- CVE-2016-310621Monitor
Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.
MediumCVSS 5.3No exploitEPSS 1%pulpproject · pulpApr 13, 2017