İçeriğe atla
Noroxi

pulpproject kayıtları

pulpproject üreticisine ait 15 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%60
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

15 kayıt
  • CVE-2024-7143
    33İzleyin

    Pulpcore: rbac permissions incorrectly assigned in tasks that create objects

    YüksekCVSS 8,3İstismar yokEPSS %1

    pulpproject · pulp7 Ağu 2024

  • CVE-2015-5263
    32İzleyin

    pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon

    YüksekCVSS 8,1İstismar yokEPSS %1

    pulpproject · pulp25 Eyl 2017

  • CVE-2016-3112
    31İzleyin

    client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which

    YüksekCVSS 7,5İstismar yokEPSS %2

    pulpproject · pulp8 Haz 2017

  • CVE-2016-3704
    31İzleyin

    Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.

    YüksekCVSS 7,5İstismar yokEPSS %2

    fedoraproject · fedora13 Haz 2017

  • CVE-2018-1090
    30İzleyin

    In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with rea

    YüksekCVSS 7,5İstismar yokEPSS %1

    pulpproject · pulp18 Haz 2018

  • CVE-2013-7450
    30İzleyin

    Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.

    YüksekCVSS 7,5İstismar yokEPSS %1

    pulpproject · pulp3 Nis 2017

  • CVE-2015-5164
    29İzleyin

    The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative

    YüksekCVSS 7,2İstismar yokEPSS %4

    pulpproject · qpid18 Eki 2017

  • CVE-2016-3108
    28İzleyin

    The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink att

    YüksekCVSS 7,1İstismar yokEPSS %0

    pulpproject · pulp8 Haz 2017

  • CVE-2018-10917
    26İzleyin

    pulp 2.16.x and possibly older is vulnerable to an improper path parsing.

    OrtaCVSS 6,5İstismar yokEPSS %1

    pulpproject · pulp15 Ağu 2018

  • CVE-2016-3111
    22İzleyin

    pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp

    OrtaCVSS 5,5İstismar yokEPSS %0

    pulpproject · pulp8 Haz 2017

  • CVE-2016-3696
    22İzleyin

    The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.

    OrtaCVSS 5,5İstismar yokEPSS %0

    fedoraproject · fedora13 Haz 2017

  • CVE-2016-3095
    22İzleyin

    server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.

    OrtaCVSS 5,5İstismar yokEPSS %0

    fedoraproject · fedora8 Haz 2017

  • CVE-2022-3644
    22İzleyin

    The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mod

    OrtaCVSS 5,5İstismar yokEPSS %0

    pulpproject · pulp ansible25 Eki 2022

  • CVE-2016-3107
    22İzleyin

    The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" dir

    OrtaCVSS 5,5İstismar yokEPSS %0

    pulpproject · pulp8 Haz 2017

  • CVE-2016-3106
    21İzleyin

    Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.

    OrtaCVSS 5,3İstismar yokEPSS %1

    pulpproject · pulp13 Nis 2017