Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5153

Опубликовано: 15 июл. 2015
Источник: redhat
CVSS2: 2.1

Описание

Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6pulpNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1243526Pulp: permissions removal issue when objects deleted

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
почти 9 лет назад

Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.

CVSS3: 8.8
github
около 4 лет назад

Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.

2.1 Low

CVSS2