2.1
CVE-2012-6119
- EPSS 0.06%
- Veröffentlicht 02.04.2013 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Candlepinproject ≫ Candlepin Version <= 0.7.2
Candlepinproject ≫ Candlepin Version0.4.5
Candlepinproject ≫ Candlepin Version0.4.11
Candlepinproject ≫ Candlepin Version0.4.27
Candlepinproject ≫ Candlepin Version0.5.5
Candlepinproject ≫ Candlepin Version0.6.3
Redhat ≫ Subscription Asset Manager Version <= 1.2.0
Redhat ≫ Subscription Asset Manager Version1.0.0
Redhat ≫ Subscription Asset Manager Version1.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.177 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:N
|