Pulp

Vendor:

First CVE: Apr 3, 2017 · Active for 9 years

14
Total CVEs
More Total CVEs than 91% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pulp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2017
9 years ago
Most Recent CVE
Aug 7, 2024
716 days ago

CVE Severity & Scoring

Pulp14 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local5 (35.7%)
Network9 (64.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (57.1%)
High0 (0.0%)
None6 (42.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
Jun 13, 20177.526NONO
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typic
Aug 7, 20248.324NONO
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An
Jun 18, 20187.524NONO
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to ob
Jun 8, 20177.524NONO
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
Apr 3, 20177.524NONO
Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same n
Aug 18, 20178.822NONO
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
Jun 8, 20177.122NONO
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user
Aug 15, 20186.521NONO
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.
Sep 25, 20178.120NONO
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
Jun 13, 20175.519NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Pulp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.8.2-115.30.9%00
2.6.318.10.9%00
2.6.218.10.9%00
2.6.118.10.9%00
2.6.018.10.9%00
2.5.318.10.9%00
2.5.218.10.9%00
2.5.118.10.9%00
2.5.018.10.9%00
2.4.418.10.9%00
2.4.318.10.9%00
2.4.218.10.9%00
2.4.118.10.9%00
2.4.018.10.9%00
2.16.416.51.1%00
2.16.216.51.1%00
2.16.116.51.1%00