VDB
CVE-2012-6119
CVE-2012-6119
PUBLISHED
CVSS 2.0999999046325684 LOW
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
EPSS 0.06% · 18.0th percentile
Risk Scores
CVSS 2.0
2.0999999046325684
EPSS Score
0.06%
18.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | subscription_asset_manager | 1.0.0, 0, 1.1.0 |
| candlepinproject | candlepin | 0.4.27, 0.5.5, 0 |
| n/a | n/a | n/a |
Exploit Intelligence
Timeline
- Apr 2, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 91719 vdb
- 52774 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=908613 url
- https://github.com/candlepin/candlepin/blob/master/candlepin.spec url
- RHSA-2013:0686 vendor-advisory
- https://github.com/candlepin/candlepin/commit/f4d93230e58b969c506b4c9778e04482a059b08c url
- https://nvd.nist.gov/vuln/detail/CVE-2012-6119 advisory