Candlepin is a subscription and entitlement-management platform whose vulnerability profile concentrates in authentication and authorization handling, with recurring exposure patterns in user-controlled key validation, credential verification, access-control logic, and sensitive information leakage. The observed weakness classes reflect the core trust boundaries in identity and permission enforcement that underpin entitlement systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Candlepinproject over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1832HIGH An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availabili | Oct 4, 2023 | 8.1 | 25 | NO | NO |
CVE-2021-4142MEDIUM The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate | Aug 24, 2022 | 5.5 | 21 | NO | NO |
CVE-2015-5187MEDIUM Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic. | Jul 25, 2017 | 6.5 | 18 | NO | NO |
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests. | Apr 2, 2013 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Candlepinproject.
Media articles that mention a CVE ID that affects a product developed by Candlepinproject — matched by CVE ID, not by vendor name.