Vulnerabilities > Candlepinproject

DATE CVE VULNERABILITY TITLE RISK
2023-10-04 CVE-2023-1832 Incorrect Authorization vulnerability in multiple products
An improper access control flaw was found in Candlepin.
network
low complexity
candlepinproject redhat CWE-863
8.1
2022-08-24 CVE-2021-4142 Authorization Bypass Through User-Controlled Key vulnerability in Candlepinproject Candlepin
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw.
local
low complexity
candlepinproject CWE-639
5.5
2017-07-25 CVE-2015-5187 Resource Management Errors vulnerability in Candlepinproject Candlepin
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
network
low complexity
candlepinproject CWE-399
6.4
2013-04-02 CVE-2012-6119 Permissions, Privileges, and Access Controls vulnerability in multiple products
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
local
low complexity
candlepinproject redhat CWE-264
2.1