CVE-2012-6119
LOW
2.1
CVSS Severity Score
Vulnerability Description
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
Affected Platforms (CPE)
📦
Candlepinproject
Candlepin
<= 0.7.2📦
Candlepinproject
Candlepin
= 0.4.5📦
Candlepinproject
Candlepin
= 0.4.11📦
Candlepinproject
Candlepin
= 0.4.27📦
Candlepinproject
Candlepin
= 0.5.5📦
Candlepinproject
Candlepin
= 0.6.3📦
Redhat
Subscription Asset Manager
<= 1.2.0📦
Redhat
Subscription Asset Manager
= 1.0.0📦
Redhat
