Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Candlepin | Candlepinproject | * | 0.7.2 (including) |
Candlepin | Candlepinproject | 0.4.5 (including) | 0.4.5 (including) |
Candlepin | Candlepinproject | 0.4.11 (including) | 0.4.11 (including) |
Candlepin | Candlepinproject | 0.4.27 (including) | 0.4.27 (including) |
Candlepin | Candlepinproject | 0.5.5 (including) | 0.5.5 (including) |
Candlepin | Candlepinproject | 0.6.3 (including) | 0.6.3 (including) |
Subscription_asset_manager | Redhat | * | 1.2.0 (including) |
Subscription_asset_manager | Redhat | 1.0.0 (including) | 1.0.0 (including) |
Subscription_asset_manager | Redhat | 1.1.0 (including) | 1.1.0 (including) |
Red Hat Subscription Asset Manager 1.2 | RedHat | candlepin-0:0.7.24-1.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | katello-0:1.2.1.1-1h.el6_4 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | katello-configure-0:1.2.3.1-4h.el6_4 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-actionpack-1:3.0.10-12.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-activemodel-0:3.0.10-3.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-delayed_job-0:2.1.4-3.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-json-0:1.7.3-2.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-rack-1:1.3.0-4.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-rails_warden-0:0.5.5-2.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-rdoc-0:3.8-6.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | thumbslug-0:0.0.28.1-1.el6_4 | * |