PT-2018-10169 · Pulp · Pulp

Laura Pardo

·

Published

2018-06-18

·

Updated

2019-10-09

·

CVE-2018-1090

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pulp versions prior to 2.16.2
Description The issue allows secrets to be passed into override config when triggering a task, making them readable to all users with read access on the distributor/importer. An attacker with API access can view these secrets.
Recommendations For versions prior to 2.16.2, update to version 2.16.2 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1090
RHSA-2018:2927

Affected Products

Pulp