CVE-2012-6119

EUVD-2012-5986
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
Affected Products (NVD)
VendorProductVersion
candlepinprojectcandlepin
𝑥
≤ 0.7.2
candlepinprojectcandlepin
0.4.5
candlepinprojectcandlepin
0.4.11
candlepinprojectcandlepin
0.4.27
candlepinprojectcandlepin
0.5.5
candlepinprojectcandlepin
0.6.3
redhatsubscription_asset_manager
𝑥
≤ 1.2.0
redhatsubscription_asset_manager
1.0.0
redhatsubscription_asset_manager
1.1.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration