Записи pulpproject
15 опубликованных записей вендора pulpproject.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 60 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-284 Improper Access Control2
- CWE-295 Improper Certificate Validation2
- CWE-256 Plaintext Storage of a Password1
- CWE-277 Insecure Inherited Permissions1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
33Наблюдать | CVE-2024-7143Эксплойта нет | Pulpcore: rbac permissions incorrectly assigned in tasks that create objectspulpproject · pulp · CWE-277 | Высокая8,3 | — | 0,6 % | 7 авг. 2024 г. |
32Наблюдать | CVE-2015-5263Эксплойта нет | pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key uponpulpproject · pulp · CWE-295 | Высокая8,1 | — | 0,9 % | 25 сент. 2017 г. |
31Наблюдать | CVE-2016-3112Эксплойта нет | client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, whichpulpproject · pulp · CWE-284 | Высокая7,5 | — | 2,2 % | 8 июн. 2017 г. |
31Наблюдать | CVE-2016-3704Эксплойта нет | Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.fedoraproject · fedora · CWE-255 | Высокая7,5 | — | 2,0 % | 13 июн. 2017 г. |
30Наблюдать | CVE-2018-1090Эксплойта нет | In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with reapulpproject · pulp · CWE-200 | Высокая7,5 | — | 1,3 % | 18 июн. 2018 г. |
30Наблюдать | CVE-2013-7450Эксплойта нет | Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.pulpproject · pulp · CWE-295 | Высокая7,5 | — | 0,9 % | 3 апр. 2017 г. |
29Наблюдать | CVE-2015-5164Эксплойта нет | The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrativepulpproject · qpid · CWE-502 | Высокая7,2 | — | 4,0 % | 18 окт. 2017 г. |
28Наблюдать | CVE-2016-3108Эксплойта нет | The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attpulpproject · pulp · CWE-59 | Высокая7,1 | — | 0,3 % | 8 июн. 2017 г. |
26Наблюдать | CVE-2018-10917Эксплойта нет | pulp 2.16.x and possibly older is vulnerable to an improper path parsing.pulpproject · pulp · CWE-22 | Средняя6,5 | — | 1,1 % | 15 авг. 2018 г. |
22Наблюдать | CVE-2016-3111Эксплойта нет | pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp pulpproject · pulp · CWE-200 | Средняя5,5 | — | 0,4 % | 8 июн. 2017 г. |
22Наблюдать | CVE-2016-3696Эксплойта нет | The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.fedoraproject · fedora · CWE-200 | Средняя5,5 | — | 0,4 % | 13 июн. 2017 г. |
22Наблюдать | CVE-2016-3095Эксплойта нет | server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.fedoraproject · fedora · CWE-200 | Средняя5,5 | — | 0,3 % | 8 июн. 2017 г. |
22Наблюдать | CVE-2022-3644Эксплойта нет | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write modpulpproject · pulp ansible · CWE-256 | Средняя5,5 | — | 0,3 % | 25 окт. 2022 г. |
22Наблюдать | CVE-2016-3107Эксплойта нет | The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" dirpulpproject · pulp · CWE-284 | Средняя5,5 | — | 0,2 % | 8 июн. 2017 г. |
21Наблюдать | CVE-2016-3106Эксплойта нет | Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.pulpproject · pulp · CWE-362 | Средняя5,3 | — | 0,9 % | 13 апр. 2017 г. |
- CVE-2024-714333Наблюдать
Pulpcore: rbac permissions incorrectly assigned in tasks that create objects
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %pulpproject · pulp7 авг. 2024 г.
- CVE-2015-526332Наблюдать
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %pulpproject · pulp25 сент. 2017 г.
- CVE-2016-311231Наблюдать
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %pulpproject · pulp8 июн. 2017 г.
- CVE-2016-370431Наблюдать
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %fedoraproject · fedora13 июн. 2017 г.
- CVE-2018-109030Наблюдать
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with rea
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pulpproject · pulp18 июн. 2018 г.
- CVE-2013-745030Наблюдать
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pulpproject · pulp3 апр. 2017 г.
- CVE-2015-516429Наблюдать
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative
ВысокаяCVSS 7,2Эксплойта нетEPSS 4 %pulpproject · qpid18 окт. 2017 г.
- CVE-2016-310828Наблюдать
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink att
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %pulpproject · pulp8 июн. 2017 г.
- CVE-2018-1091726Наблюдать
pulp 2.16.x and possibly older is vulnerable to an improper path parsing.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %pulpproject · pulp15 авг. 2018 г.
- CVE-2016-311122Наблюдать
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp
СредняяCVSS 5,5Эксплойта нетEPSS 0 %pulpproject · pulp8 июн. 2017 г.
- CVE-2016-369622Наблюдать
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %fedoraproject · fedora13 июн. 2017 г.
- CVE-2016-309522Наблюдать
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %fedoraproject · fedora8 июн. 2017 г.
- CVE-2022-364422Наблюдать
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mod
СредняяCVSS 5,5Эксплойта нетEPSS 0 %pulpproject · pulp ansible25 окт. 2022 г.
- CVE-2016-310722Наблюдать
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" dir
СредняяCVSS 5,5Эксплойта нетEPSS 0 %pulpproject · pulp8 июн. 2017 г.
- CVE-2016-310621Наблюдать
Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %pulpproject · pulp13 апр. 2017 г.