Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.1)0.32%—PulpcoreAI24/9/20261/10/2026
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with…
Pendiente de análisisMedia (5.4)0.24%—PulpcoreAI1/9/20261/9/2026
A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An…
Pendiente de análisisMedia (6.4)0.37%—Galaxy NGAIPulpAI25/8/202628/8/2026
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or cloud instance metadata endpoints. A…
Pendiente de análisisCrítica (9)1.2%—PulpcoreAI20/7/202622/7/2026
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal…
AplazadaCrítica (9.3)1.4%—PulpyAI12/5/202617/6/2026
Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A validateFsPath() function is supposed to sandbox this access, but its blocklist is incomplete. Any…
ModificadaAlta (8.3)0.61%—Pulpproject Pulp7/8/202417/6/2026
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticated user. For objects…
ModificadaMedia (5.5)0.29%—Pulpproject Pulp AnsibleRedhat Ansible Automation PlatformRedhat SatelliteRedhat Update Infrastructure25/10/202217/6/2026
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
ModificadaMedia (6.5)1.1%—Pulpproject Pulp15/8/201817/6/2026
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.
ModificadaAlta (7.5)1.3%—Pulpproject PulpFedoraproject FedoraRedhat Satellite18/6/201817/6/2026
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
ModificadaAlta (7.2)4.0%—Pulpproject Qpid18/10/201717/6/2026
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message, related to a pickle processing problem in pulp.
ModificadaAlta (8.1)0.87%—Pulpproject Pulp25/9/201717/6/2026
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.
ModificadaAlta (8.8)1.2%—Pulp Project Pulp18/8/201717/6/2026
Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.
ModificadaAlta (7.5)2.0%—Fedoraproject FedoraPulpproject Pulp13/6/201717/6/2026
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
ModificadaMedia (5.5)0.35%—Fedoraproject FedoraPulpproject Pulp13/6/201717/6/2026
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
ModificadaMedia (5.5)0.30%—Fedoraproject FedoraPulpproject Pulp8/6/201717/6/2026
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
ModificadaAlta (7.5)2.2%—Pulpproject Pulp8/6/201717/6/2026
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading /etc/pki/pulp/consumer/consumer-cert, and authenticating as a consumer…
ModificadaMedia (5.5)0.39%—Pulpproject Pulp8/6/201717/6/2026
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files…
ModificadaAlta (7.1)0.26%—Pulpproject Pulp8/6/201717/6/2026
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
ModificadaMedia (5.5)0.20%—Pulpproject Pulp8/6/201717/6/2026
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data.
ModificadaMedia (5.3)0.94%—Pulpproject Pulp13/4/201717/6/2026
Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.
ModificadaAlta (7.5)0.87%—Pulpproject Pulp3/4/201717/6/2026
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.