Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2016-3704
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.005
EPSS Ranking
66.5%
CVSS Severity
CVSS v3 Score
7.5
CVSS v2 Score
5.0
References
https://access.redhat.com/errata/RHSA-2018:0336
https://bugzilla.redhat.com/show_bug.cgi?id=1330264
https://docs.pulpproject.org/user-guide/release-notes/2.8.x.html#pulp-2-8-5
https://github.com/pulp/pulp/blob/pulp-2.8.2-1/server/bin/pulp-qpid-ssl-cfg#L25
https://github.com/pulp/pulp/blob/pulp-2.8.2-1/server/bin/pulp-qpid-ssl-cfg#L97-L105
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YM2LCC7QBRCK4LTN5EZT5OHTVAR3MYTY/
https://pulp.plan.io/issues/1858
https://access.redhat.com/errata/RHSA-2018:0336
https://bugzilla.redhat.com/show_bug.cgi?id=1330264
https://docs.pulpproject.org/user-guide/release-notes/2.8.x.html#pulp-2-8-5
https://github.com/pulp/pulp/blob/pulp-2.8.2-1/server/bin/pulp-qpid-ssl-cfg#L25
https://github.com/pulp/pulp/blob/pulp-2.8.2-1/server/bin/pulp-qpid-ssl-cfg#L97-L105
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YM2LCC7QBRCK4LTN5EZT5OHTVAR3MYTY/
https://pulp.plan.io/issues/1858
Products affected by CVE-2016-3704
Pulpproject
»
Pulp
»
Version:
2.2.1-1
cpe:2.3:a:pulpproject:pulp:2.2.1-1
Pulpproject
»
Pulp
»
Version:
2.4.0
cpe:2.3:a:pulpproject:pulp:2.4.0
Pulpproject
»
Pulp
»
Version:
2.4.1
cpe:2.3:a:pulpproject:pulp:2.4.1
Pulpproject
»
Pulp
»
Version:
2.4.2
cpe:2.3:a:pulpproject:pulp:2.4.2
Pulpproject
»
Pulp
»
Version:
2.4.3
cpe:2.3:a:pulpproject:pulp:2.4.3
Pulpproject
»
Pulp
»
Version:
2.4.4
cpe:2.3:a:pulpproject:pulp:2.4.4
Pulpproject
»
Pulp
»
Version:
2.5.0
cpe:2.3:a:pulpproject:pulp:2.5.0
Pulpproject
»
Pulp
»
Version:
2.5.1
cpe:2.3:a:pulpproject:pulp:2.5.1
Pulpproject
»
Pulp
»
Version:
2.5.2
cpe:2.3:a:pulpproject:pulp:2.5.2
Pulpproject
»
Pulp
»
Version:
2.5.3
cpe:2.3:a:pulpproject:pulp:2.5.3
Pulpproject
»
Pulp
»
Version:
2.6.0
cpe:2.3:a:pulpproject:pulp:2.6.0
Pulpproject
»
Pulp
»
Version:
2.6.1
cpe:2.3:a:pulpproject:pulp:2.6.1
Pulpproject
»
Pulp
»
Version:
2.6.2
cpe:2.3:a:pulpproject:pulp:2.6.2
Pulpproject
»
Pulp
»
Version:
2.6.3
cpe:2.3:a:pulpproject:pulp:2.6.3
Pulpproject
»
Pulp
»
Version:
2.6.4
cpe:2.3:a:pulpproject:pulp:2.6.4
Pulpproject
»
Pulp
»
Version:
2.6.5
cpe:2.3:a:pulpproject:pulp:2.6.5
Pulpproject
»
Pulp
»
Version:
2.7.0
cpe:2.3:a:pulpproject:pulp:2.7.0
Pulpproject
»
Pulp
»
Version:
2.8.0
cpe:2.3:a:pulpproject:pulp:2.8.0
Pulpproject
»
Pulp
»
Version:
2.8.1
cpe:2.3:a:pulpproject:pulp:2.8.1
Pulpproject
»
Pulp
»
Version:
2.8.2
cpe:2.3:a:pulpproject:pulp:2.8.2
Pulpproject
»
Pulp
»
Version:
2.8.2-1
cpe:2.3:a:pulpproject:pulp:2.8.2-1
Pulpproject
»
Pulp
»
Version:
2.8.3
cpe:2.3:a:pulpproject:pulp:2.8.3
Pulpproject
»
Pulp
»
Version:
2.8.4
cpe:2.3:a:pulpproject:pulp:2.8.4
Fedoraproject
»
Fedora
»
Version:
24
cpe:2.3:o:fedoraproject:fedora:24
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved