Medium severity5.5NVD Advisory· Published Jun 18, 2018· Updated Jun 17, 2026
CVE-2018-1090
CVE-2018-1090
Description
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5<2.16.2+ 1 more
- (no CPE)range: <2.16.2
- cpe:2.3:a:pulpproject:pulp:*:*:*:*:*:*:*:*range: <2.16.2
- cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- access.redhat.com/errata/RHSA-2018:2927nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- pulp.plan.io/issues/3521nvdVendor Advisory
News mentions
0No linked articles in our index yet.