CVE-2024-7143 is a high-severity flaw in the Pulp package, affecting pulpproject pulp, pulpproject ansible_automation_platform, redhat pulp, and redhat ansible_automation_platform. This vulnerability allows an attacker to gain unauthorized access to objects created within tasks due to incorrect assignment of permissions. The flaw, with a CVSS score of 8.3, stems from a logic error where the oldest user with task permissions is incorrectly assigned as the creator for all objects within a task, rather than the actual user dispatching the task, leading to potential compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:pulpproject:pulp:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.