Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.32% | — | PulpcoreAI | 24/9/2026 | 1/10/2026 | A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with… | |
| Pendiente de análisis | Media (5.4) | 0.24% | — | PulpcoreAI | 1/9/2026 | 1/9/2026 | A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An… | |
| Pendiente de análisis | Media (6.4) | 0.37% | — | Galaxy NGAIPulpAI | 25/8/2026 | 28/8/2026 | A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or cloud instance metadata endpoints. A… | |
| Pendiente de análisis | Crítica (9) | 1.2% | — | PulpcoreAI | 20/7/2026 | 22/7/2026 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal… | |
| Aplazada | Crítica (9.3) | 1.4% | — | PulpyAI | 12/5/2026 | 17/6/2026 | Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A validateFsPath() function is supposed to sandbox this access, but its blocklist is incomplete. Any… | |
| Modificada | Alta (8.3) | 0.61% | — | Pulpproject Pulp | 7/8/2024 | 17/6/2026 | A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticated user. For objects… | |
| Modificada | Media (5.5) | 0.29% | — | Pulpproject Pulp AnsibleRedhat Ansible Automation PlatformRedhat SatelliteRedhat Update Infrastructure | 25/10/2022 | 17/6/2026 | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. | |
| Modificada | Media (6.5) | 1.1% | — | Pulpproject Pulp | 15/8/2018 | 17/6/2026 | pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories. | |
| Modificada | Alta (7.5) | 1.3% | — | Pulpproject PulpFedoraproject FedoraRedhat Satellite | 18/6/2018 | 17/6/2026 | In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets. | |
| Modificada | Alta (7.2) | 4.0% | — | Pulpproject Qpid | 18/10/2017 | 17/6/2026 | The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message, related to a pickle processing problem in pulp. | |
| Modificada | Alta (8.1) | 0.87% | — | Pulpproject Pulp | 25/9/2017 | 17/6/2026 | pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration. | |
| Modificada | Alta (8.8) | 1.2% | — | Pulp Project Pulp | 18/8/2017 | 17/6/2026 | Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name. | |
| Modificada | Alta (7.5) | 2.0% | — | Fedoraproject FedoraPulpproject Pulp | 13/6/2017 | 17/6/2026 | Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords. | |
| Modificada | Media (5.5) | 0.35% | — | Fedoraproject FedoraPulpproject Pulp | 13/6/2017 | 17/6/2026 | The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key. | |
| Modificada | Media (5.5) | 0.30% | — | Fedoraproject FedoraPulpproject Pulp | 8/6/2017 | 17/6/2026 | server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key. | |
| Modificada | Alta (7.5) | 2.2% | — | Pulpproject Pulp | 8/6/2017 | 17/6/2026 | client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading /etc/pki/pulp/consumer/consumer-cert, and authenticating as a consumer… | |
| Modificada | Media (5.5) | 0.39% | — | Pulpproject Pulp | 8/6/2017 | 17/6/2026 | pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files… | |
| Modificada | Alta (7.1) | 0.26% | — | Pulpproject Pulp | 8/6/2017 | 17/6/2026 | The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack. | |
| Modificada | Media (5.5) | 0.20% | — | Pulpproject Pulp | 8/6/2017 | 17/6/2026 | The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data. | |
| Modificada | Media (5.3) | 0.94% | — | Pulpproject Pulp | 13/4/2017 | 17/6/2026 | Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner. | |
| Modificada | Alta (7.5) | 0.87% | — | Pulpproject Pulp | 3/4/2017 | 17/6/2026 | Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations. |