Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Candlepinproject

First CVE: Apr 2, 2013Active for: 13 yearsTotal CVEs: 4

Candlepin is a subscription and entitlement-management platform whose vulnerability profile concentrates in authentication and authorization handling, with recurring exposure patterns in user-controlled key validation, credential verification, access-control logic, and sensitive information leakage. The observed weakness classes reflect the core trust boundaries in identity and permission enforcement that underpin entitlement systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Candlepinproject over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 2, 2013
13 years ago
Most Recent CVE
Oct 4, 2023
1,024 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1832HIGH
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availabili
Oct 4, 20238.125NONO
CVE-2021-4142MEDIUM
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate
Aug 24, 20225.521NONO
CVE-2015-5187MEDIUM
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
Jul 25, 20176.518NONO
CVE-2012-6119LOW
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
Apr 2, 20132.113NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
25%
50%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (25.0%)
Network2 (50.0%)
Unknown1 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High0 (0.0%)
Unknown1 (25.0%)
User Interaction
None3 (75.0%)
Unknown1 (25.0%)
Required0 (0.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None1 (25.0%)
Unknown1 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Candlepinproject.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Candlepinproject — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Candlepinproject's Products

View all 1 CNAs →

Top CWEs