Pulpproject maintains a content and artifact repository management platform used across enterprise software supply chains and automation contexts, with a lean product portfolio centered on Pulp, Pulp Ansible, and related messaging components. Its vulnerability profile recurs through information-disclosure and access-control weaknesses—including sensitive-data exposure, improper authorization, certificate validation flaws, race conditions, and untrusted deserialization—that are characteristic of distributed repository and messaging systems handling credentials, packages, and system state. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pulpproject over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3704HIGH Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords. | Jun 13, 2017 | 7.5 | 26 | NO | NO |
CVE-2024-7143HIGH A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typic | Aug 7, 2024 | 8.3 | 24 | NO | NO |
CVE-2018-1090HIGH In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An | Jun 18, 2018 | 7.5 | 24 | NO | NO |
CVE-2015-5164HIGH The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to exe | Oct 18, 2017 | 7.2 | 24 | NO | NO |
CVE-2016-3112HIGH client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to ob | Jun 8, 2017 | 7.5 | 24 | NO | NO |
CVE-2013-7450HIGH Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations. | Apr 3, 2017 | 7.5 | 24 | NO | NO |
CVE-2015-5153HIGH Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same n | Aug 18, 2017 | 8.8 | 22 | NO | NO |
CVE-2016-3108HIGH The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack. | Jun 8, 2017 | 7.1 | 22 | NO | NO |
CVE-2018-10917MEDIUM pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user | Aug 15, 2018 | 6.5 | 21 | NO | NO |
CVE-2022-3644MEDIUM The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it a | Oct 25, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pulpproject.
Media articles that mention a CVE ID that affects a product developed by Pulpproject — matched by CVE ID, not by vendor name.