Pulpproject / Pulp
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-7143 | Pulpcore: rbac permissions incorrectly assigned in tasks that create objects | HIGH | 8.6 | Aug 7, 2024 |
| CVE-2018-10917 | pulp: Improper path parsing leads to overwriting of iso repositories | MEDIUM | 6.8 | Aug 15, 2018 |
| CVE-2018-1090 | pulp: sensitive credentials revealed through the API | HIGH | 7.5 | Jun 18, 2018 |
| CVE-2015-5263 | pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration. | HIGH | 8.1 | Sep 25, 2017 |
| CVE-2016-3704 | pulp: Unsafe use of bash $RANDOM for NSS DB password and seed | HIGH | 7.5 | Jun 13, 2017 |
| CVE-2016-3696 | pulp: Leakage of CA key in pulp-qpid-ssl-cfg | MEDIUM | 6.5 | Jun 13, 2017 |
| CVE-2016-3095 | pulp: Potential leakage when generating new CA key in /tmp | MEDIUM | 5.5 | Jun 8, 2017 |
| CVE-2016-3112 | pulp: Agent certificate containing private key is stored in world-readable file | HIGH | 7.5 | Jun 8, 2017 |
| CVE-2016-3111 | pulp: Race condition when generating RSA keys for authenticating messages between server and consumers | MEDIUM | 5.5 | Jun 8, 2017 |
| CVE-2016-3108 | pulp: Insecure temporary file used when generating certificate for Pulp Nodes | HIGH | 7.1 | Jun 8, 2017 |
| CVE-2016-3107 | pulp: Node certificate containing private key stored in world-readable file | MEDIUM | 5.5 | Jun 8, 2017 |
| CVE-2016-3106 | pulp: Insecure creation of temporary directory when generating new CA key | MEDIUM | 5.3 | Apr 13, 2017 |
| CVE-2013-7450 | pulp: distributed with CA from public code repository | HIGH | 7.5 | Apr 3, 2017 |
Showing 1 to 13 of 13 CVEs