ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-1832
An improper access control flaw was found in Candlepin.

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

NVD description · AI analysis pending
8.1<1%
  • candlepinproject candlepin
  • candlepinproject satellite
CVE-2021-4142
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw.

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

NVD description · AI analysis pending
5.5<1%
  • candlepinproject candlepin