Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-7628

20
FAUCET Score

CVE-2019-7628 describes a vulnerability in Pagure version 5.2 where API keys are leaked to users via email, primarily due to the API token expiration reminder cron job. This flaw allows attackers to intercept these emails through man-in-the-middle attacks, as many email servers do not validate TLS certificates, thereby gaining unauthorized access to Pagure on behalf of other users. The vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack vector with high confidentiality impact but high attack complexity due to the reliance on email interception. While the issue could lead to full account compromise, it does not affect integrity or availability. There is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit or Nuclei. The CVE has received minimal community discussion and media coverage, suggesting a low level of public awareness or attention.

Impacted Technologies

VendorProductVersion(s)CPE
5.2CPE matchmatch criteria
cpe:2.3:a:redhat:pagure:5.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.9MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.90%
Probability of exploitation in next 30 days
EPSS Percentile
56.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0090 is in the 13th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

pagure.io / pagure/c/9905fb1e64341822366b6ab1d414d2baa230af0a
Issue TrackingPatchVendor Advisory
pagure.io / pagure/issue/4230
Issue TrackingPatchVendor Advisory
pagure.io / pagure/issue/4252
Broken Link
pagure.io / pagure/issue/4253
Broken Link
pagure.io / pagure/pull-request/4254
Issue TrackingPatchVendor Advisory