Vulnerability Details CVE-2018-1090
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.8%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 5.0
Products affected by CVE-2018-1090
-
cpe:2.3:a:pulpproject:pulp:2.10.0
-
cpe:2.3:a:pulpproject:pulp:2.10.1
-
cpe:2.3:a:pulpproject:pulp:2.10.2
-
cpe:2.3:a:pulpproject:pulp:2.11.0
-
cpe:2.3:a:pulpproject:pulp:2.11.1
-
cpe:2.3:a:pulpproject:pulp:2.12.0
-
cpe:2.3:a:pulpproject:pulp:2.12.1
-
cpe:2.3:a:pulpproject:pulp:2.12.2
-
cpe:2.3:a:pulpproject:pulp:2.13.0
-
cpe:2.3:a:pulpproject:pulp:2.13.1
-
cpe:2.3:a:pulpproject:pulp:2.14.0
-
cpe:2.3:a:pulpproject:pulp:2.14.1
-
cpe:2.3:a:pulpproject:pulp:2.14.2
-
cpe:2.3:a:pulpproject:pulp:2.14.3
-
cpe:2.3:a:pulpproject:pulp:2.15.0
-
cpe:2.3:a:pulpproject:pulp:2.16.0
-
cpe:2.3:a:pulpproject:pulp:2.16.1
-
cpe:2.3:a:pulpproject:pulp:2.2.1-1
-
cpe:2.3:a:pulpproject:pulp:2.4.0
-
cpe:2.3:a:pulpproject:pulp:2.4.1
-
cpe:2.3:a:pulpproject:pulp:2.4.2
-
cpe:2.3:a:pulpproject:pulp:2.4.3
-
cpe:2.3:a:pulpproject:pulp:2.4.4
-
cpe:2.3:a:pulpproject:pulp:2.5.0
-
cpe:2.3:a:pulpproject:pulp:2.5.1
-
cpe:2.3:a:pulpproject:pulp:2.5.2
-
cpe:2.3:a:pulpproject:pulp:2.5.3
-
cpe:2.3:a:pulpproject:pulp:2.6.0
-
cpe:2.3:a:pulpproject:pulp:2.6.1
-
cpe:2.3:a:pulpproject:pulp:2.6.2
-
cpe:2.3:a:pulpproject:pulp:2.6.3
-
cpe:2.3:a:pulpproject:pulp:2.6.4
-
cpe:2.3:a:pulpproject:pulp:2.6.5
-
cpe:2.3:a:pulpproject:pulp:2.7.0
-
cpe:2.3:a:pulpproject:pulp:2.8.0
-
cpe:2.3:a:pulpproject:pulp:2.8.1
-
cpe:2.3:a:pulpproject:pulp:2.8.2
-
cpe:2.3:a:pulpproject:pulp:2.8.2-1
-
cpe:2.3:a:pulpproject:pulp:2.8.3
-
cpe:2.3:a:pulpproject:pulp:2.8.4
-
cpe:2.3:a:pulpproject:pulp:2.8.5
-
cpe:2.3:a:pulpproject:pulp:2.8.6
-
cpe:2.3:a:pulpproject:pulp:2.8.7
-
cpe:2.3:a:pulpproject:pulp:2.9.0
-
cpe:2.3:a:pulpproject:pulp:2.9.1
-
cpe:2.3:a:pulpproject:pulp:2.9.2
-
cpe:2.3:a:pulpproject:pulp:2.9.3
-
cpe:2.3:a:redhat:satellite:6.4
-
cpe:2.3:o:fedoraproject:fedora:-