Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5153

Опубликовано: 15 июл. 2015
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6pulpNot affected
RHUI for RHEL 6pulpNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1243526Pulp: permissions removal issue when objects deleted

EPSS

Процентиль: 62%
0.00428
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
больше 8 лет назад

Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.

CVSS3: 8.8
github
больше 3 лет назад

Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.

EPSS

Процентиль: 62%
0.00428
Низкий

2.1 Low

CVSS2