Vulnerabilities > Candlepinproject > Candlepin > 0.4.5

DATE CVE VULNERABILITY TITLE RISK
2023-10-04 CVE-2023-1832 Incorrect Authorization vulnerability in multiple products
An improper access control flaw was found in Candlepin.
network
low complexity
candlepinproject redhat CWE-863
8.1
2013-04-02 CVE-2012-6119 Permissions, Privileges, and Access Controls vulnerability in multiple products
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
local
low complexity
candlepinproject redhat CWE-264
2.1