pulpproject kayıtları
pulpproject üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %60
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-284 Improper Access Control2
- CWE-295 Improper Certificate Validation2
- CWE-256 Plaintext Storage of a Password1
- CWE-277 Insecure Inherited Permissions1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2024-7143İstismar yok | Pulpcore: rbac permissions incorrectly assigned in tasks that create objectspulpproject · pulp · CWE-277 | Yüksek8,3 | — | %0,6 | 7 Ağu 2024 |
32İzleyin | CVE-2015-5263İstismar yok | pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key uponpulpproject · pulp · CWE-295 | Yüksek8,1 | — | %0,9 | 25 Eyl 2017 |
31İzleyin | CVE-2016-3112İstismar yok | client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, whichpulpproject · pulp · CWE-284 | Yüksek7,5 | — | %2,2 | 8 Haz 2017 |
31İzleyin | CVE-2016-3704İstismar yok | Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.fedoraproject · fedora · CWE-255 | Yüksek7,5 | — | %2,0 | 13 Haz 2017 |
30İzleyin | CVE-2018-1090İstismar yok | In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with reapulpproject · pulp · CWE-200 | Yüksek7,5 | — | %1,3 | 18 Haz 2018 |
30İzleyin | CVE-2013-7450İstismar yok | Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.pulpproject · pulp · CWE-295 | Yüksek7,5 | — | %0,9 | 3 Nis 2017 |
29İzleyin | CVE-2015-5164İstismar yok | The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrativepulpproject · qpid · CWE-502 | Yüksek7,2 | — | %4,0 | 18 Eki 2017 |
28İzleyin | CVE-2016-3108İstismar yok | The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attpulpproject · pulp · CWE-59 | Yüksek7,1 | — | %0,3 | 8 Haz 2017 |
26İzleyin | CVE-2018-10917İstismar yok | pulp 2.16.x and possibly older is vulnerable to an improper path parsing.pulpproject · pulp · CWE-22 | Orta6,5 | — | %1,1 | 15 Ağu 2018 |
22İzleyin | CVE-2016-3111İstismar yok | pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp pulpproject · pulp · CWE-200 | Orta5,5 | — | %0,4 | 8 Haz 2017 |
22İzleyin | CVE-2016-3696İstismar yok | The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.fedoraproject · fedora · CWE-200 | Orta5,5 | — | %0,4 | 13 Haz 2017 |
22İzleyin | CVE-2016-3095İstismar yok | server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.fedoraproject · fedora · CWE-200 | Orta5,5 | — | %0,3 | 8 Haz 2017 |
22İzleyin | CVE-2022-3644İstismar yok | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write modpulpproject · pulp ansible · CWE-256 | Orta5,5 | — | %0,3 | 25 Eki 2022 |
22İzleyin | CVE-2016-3107İstismar yok | The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" dirpulpproject · pulp · CWE-284 | Orta5,5 | — | %0,2 | 8 Haz 2017 |
21İzleyin | CVE-2016-3106İstismar yok | Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.pulpproject · pulp · CWE-362 | Orta5,3 | — | %0,9 | 13 Nis 2017 |
- CVE-2024-714333İzleyin
Pulpcore: rbac permissions incorrectly assigned in tasks that create objects
YüksekCVSS 8,3İstismar yokEPSS %1pulpproject · pulp7 Ağu 2024
- CVE-2015-526332İzleyin
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon
YüksekCVSS 8,1İstismar yokEPSS %1pulpproject · pulp25 Eyl 2017
- CVE-2016-311231İzleyin
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which
YüksekCVSS 7,5İstismar yokEPSS %2pulpproject · pulp8 Haz 2017
- CVE-2016-370431İzleyin
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
YüksekCVSS 7,5İstismar yokEPSS %2fedoraproject · fedora13 Haz 2017
- CVE-2018-109030İzleyin
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with rea
YüksekCVSS 7,5İstismar yokEPSS %1pulpproject · pulp18 Haz 2018
- CVE-2013-745030İzleyin
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
YüksekCVSS 7,5İstismar yokEPSS %1pulpproject · pulp3 Nis 2017
- CVE-2015-516429İzleyin
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative
YüksekCVSS 7,2İstismar yokEPSS %4pulpproject · qpid18 Eki 2017
- CVE-2016-310828İzleyin
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink att
YüksekCVSS 7,1İstismar yokEPSS %0pulpproject · pulp8 Haz 2017
- CVE-2018-1091726İzleyin
pulp 2.16.x and possibly older is vulnerable to an improper path parsing.
OrtaCVSS 6,5İstismar yokEPSS %1pulpproject · pulp15 Ağu 2018
- CVE-2016-311122İzleyin
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp
OrtaCVSS 5,5İstismar yokEPSS %0pulpproject · pulp8 Haz 2017
- CVE-2016-369622İzleyin
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
OrtaCVSS 5,5İstismar yokEPSS %0fedoraproject · fedora13 Haz 2017
- CVE-2016-309522İzleyin
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
OrtaCVSS 5,5İstismar yokEPSS %0fedoraproject · fedora8 Haz 2017
- CVE-2022-364422İzleyin
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mod
OrtaCVSS 5,5İstismar yokEPSS %0pulpproject · pulp ansible25 Eki 2022
- CVE-2016-310722İzleyin
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" dir
OrtaCVSS 5,5İstismar yokEPSS %0pulpproject · pulp8 Haz 2017
- CVE-2016-310621İzleyin
Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.
OrtaCVSS 5,3İstismar yokEPSS %1pulpproject · pulp13 Nis 2017