VendorsCandlepinprojectcandlepinall versions
Vulnerabilities

Candlepinproject Candlepin

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-1832
Improper authorization check in the server component
Published 2023-10-04 · Modified
8.1EPSS 0.006
CVE-2015-5187
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
Published 2017-07-25 · Modified
6.5EPSS 0.020
CVE-2021-4142
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
Published 2022-08-24 · Modified
5.5EPSS 0.002
CVE-2012-6119
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
Published 2013-04-02 · Modified
2.1EPSS 0.004