2.1

CVE-2012-6119

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

Data is provided by the National Vulnerability Database (NVD)
CandlepinprojectCandlepin Version <= 0.7.2
CandlepinprojectCandlepin Version0.4.5
CandlepinprojectCandlepin Version0.4.11
CandlepinprojectCandlepin Version0.4.27
CandlepinprojectCandlepin Version0.5.5
CandlepinprojectCandlepin Version0.6.3
RedhatSubscription Asset Manager Version <= 1.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.138
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N