Medium severity6.8NVD Advisory· Published Oct 4, 2023· Updated Jun 17, 2026
CVE-2023-1832
CVE-2023-1832
Description
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:candlepinproject:candlepin:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:candlepinproject:candlepin:*:*:*:*:*:*:*:*range: <4.3.7-3
- (no CPE)
Patches
Vulnerability mechanics
References
2- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchVendor Advisory
- access.redhat.com/security/cve/CVE-2023-1832nvdVendor Advisory
News mentions
0No linked articles in our index yet.