CVE-2012-6119

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
candlepinprojectcandlepin
𝑥
≤ 0.7.2
candlepinprojectcandlepin
0.4.5
candlepinprojectcandlepin
0.4.11
candlepinprojectcandlepin
0.4.27
candlepinprojectcandlepin
0.5.5
candlepinprojectcandlepin
0.6.3
redhatsubscription_asset_manager
𝑥
≤ 1.2.0
redhatsubscription_asset_manager
1.0.0
redhatsubscription_asset_manager
1.1.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration