Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pulp Project

First CVE: Apr 3, 2017Active for: 9 yearsTotal CVEs: 16

Pulp Project develops a content and artifact repository management platform that serves as a centralized storage and distribution system for software packages and updates across enterprise environments. Its vulnerability footprint centers on the Pulp product itself, with observed weaknesses around improper permissions and access control mechanisms. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
Bottom 1%
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pulp Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2017
9 years ago
Most Recent CVE
Aug 7, 2024
716 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-3704HIGH
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
Jun 13, 20177.526NONO
CVE-2024-7143HIGH
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typic
Aug 7, 20248.324NONO
CVE-2018-1090HIGH
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An
Jun 18, 20187.524NONO
CVE-2015-5164HIGH
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to exe
Oct 18, 20177.224NONO
CVE-2016-3112HIGH
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to ob
Jun 8, 20177.524NONO
CVE-2013-7450HIGH
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
Apr 3, 20177.524NONO
CVE-2015-5153HIGH
Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same n
Aug 18, 20178.822NONO
CVE-2016-3108HIGH
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
Jun 8, 20177.122NONO
CVE-2018-10917MEDIUM
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user
Aug 15, 20186.521NONO
CVE-2022-3644MEDIUM
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it a
Oct 25, 20225.520NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
44%
56%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (37.5%)
Network10 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low9 (56.3%)
High1 (6.3%)
None6 (37.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pulp Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pulp Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pulp Project's Products

View all 2 CNAs →

Top CWEs