Skip to main content

Vendor/product archive

pulpproject / pulp CVEs

Beta · best-effort

13 CVEs tagged to pulpproject / pulp0 Critical, 6 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2018-10917

Published Aug 15, 2018

pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' use…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5263

Published Sep 25, 2017

pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3112

Published Jun 8, 2017

client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3111

Published Jun 8, 2017

pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3108

Published Jun 8, 2017

The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3107

Published Jun 8, 2017

The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gai…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3106

Published Apr 13, 2017

Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7450

Published Apr 3, 2017

Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1