VYPR
Vendor

Candlepinproject

Sign in to watch
Products
1
CVEs
2
Across products
7
Status
Private

Products

1

Recent CVEs

2
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2015-5187Med0.426.50.00Jul 25, 2017Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
CVE-2012-61190.000.00Apr 2, 2013Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.