VYPR
Medium severity6.8NVD Advisory· Published Oct 4, 2023· Updated Jun 17, 2026

CVE-2023-1832

CVE-2023-1832

Description

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Red Hat/Satellitecpe-rescue2 versions
    cpe:/a:redhat:satellite:6+ 1 more
    • cpe:/a:redhat:satellite:6
    • cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:candlepinproject:candlepin:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:candlepinproject:candlepin:*:*:*:*:*:*:*:*range: <4.3.7-3
    • (no CPE)
  • Red Hat/Candlepinllm-create

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.