VYPR

Candlepin

by Red Hat

Source repositories

CVEs (3)

  • CVE-2019-3891HigApr 15, 2019
    risk 0.51cvss 7.8epss 0.01

    It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent…

  • CVE-2023-1832MedOct 4, 2023
    risk 0.44cvss 6.8epss 0.01

    An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

  • CVE-2021-4142MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.