Pulp Project develops a content and artifact repository management platform that serves as a centralized storage and distribution system for software packages and updates across enterprise environments. Its vulnerability footprint centers on the Pulp product itself, with observed weaknesses around improper permissions and access control mechanisms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pulp Project over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3704HIGH Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords. | Jun 13, 2017 | 7.5 | 26 | NO | NO |
CVE-2024-7143HIGH A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typic | Aug 7, 2024 | 8.3 | 24 | NO | NO |
CVE-2018-1090HIGH In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An | Jun 18, 2018 | 7.5 | 24 | NO | NO |
CVE-2015-5164HIGH The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to exe | Oct 18, 2017 | 7.2 | 24 | NO | NO |
CVE-2016-3112HIGH client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to ob | Jun 8, 2017 | 7.5 | 24 | NO | NO |
CVE-2013-7450HIGH Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations. | Apr 3, 2017 | 7.5 | 24 | NO | NO |
CVE-2015-5153HIGH Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same n | Aug 18, 2017 | 8.8 | 22 | NO | NO |
CVE-2016-3108HIGH The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack. | Jun 8, 2017 | 7.1 | 22 | NO | NO |
CVE-2018-10917MEDIUM pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user | Aug 15, 2018 | 6.5 | 21 | NO | NO |
CVE-2022-3644MEDIUM The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it a | Oct 25, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pulp Project.
Media articles that mention a CVE ID that affects a product developed by Pulp Project — matched by CVE ID, not by vendor name.