CVE-2012-6119

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
candlepinprojectcandlepin
𝑥
≤ 0.7.2
candlepinprojectcandlepin
0.4.5
candlepinprojectcandlepin
0.4.11
candlepinprojectcandlepin
0.4.27
candlepinprojectcandlepin
0.5.5
candlepinprojectcandlepin
0.6.3
redhatsubscription_asset_manager
𝑥
≤ 1.2.0
redhatsubscription_asset_manager
1.0.0
redhatsubscription_asset_manager
1.1.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration