CVE-2019-7628 describes a vulnerability in Pagure version 5.2 where API keys are leaked to users via email, primarily due to the API token expiration reminder cron job. This flaw allows attackers to intercept these emails through man-in-the-middle attacks, as many email servers do not validate TLS certificates, thereby gaining unauthorized access to Pagure on behalf of other users. The vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack vector with high confidentiality impact but high attack complexity due to the reliance on email interception. While the issue could lead to full account compromise, it does not affect integrity or availability. There is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit or Nuclei. The CVE has received minimal community discussion and media coverage, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2CPE matchmatch criteria | cpe:2.3:a:redhat:pagure:5.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.