CVE-2012-6119 PUBLISHED CVSS 2.0999999046325684 LOW

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

EPSS 0.06% · 17.7th percentile

Risk Scores

CVSS v2.0
2.0999999046325684
EPSS Score
0.06%
17.7th percentile

Affected Products

VendorProductVersions
redhatsubscription_asset_manager1.1.0, 0, 1.0.0
candlepinprojectcandlepin0.4.11, 0.4.27, 0.6.3
n/an/an/a

Timeline

References

Open in Interactive Console →