| Vulnerability Name: | CVE-2013-7450 (CCN-112328) | ||||||||||||
| Assigned: | 2016-04-18 | ||||||||||||
| Published: | 2016-04-18 | ||||||||||||
| Updated: | 2017-04-26 | ||||||||||||
| Summary: | Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations. | ||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-295 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2013-7450 Source: CCN Type: oss-sec Mailing List, Mon, 18 Apr 2016 11:11:35 -0400 (EDT) Re: CVE request - Pulp < 2.3.0 shipped the same authentication CA key/cert to all users Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160418 CVE-2013-7450: Pulp < 2.3.0 distributed the same CA key to all users Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20160418 Re: CVE request - Pulp < 2.3.0 shipped the same authentication CA key/cert to all users Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160519 Pulp 2.8.3 Released to address multiple CVEs Source: CCN Type: Red Hat Bugzilla Bug 1003326 CVE-2013-7450: All users who install pulp-server will have the same CA certificate and key that is in our public code repository Source: CONFIRM Type: Issue Tracking, Patch https://bugzilla.redhat.com/show_bug.cgi?id=1003326 Source: CONFIRM Type: Issue Tracking, Patch https://bugzilla.redhat.com/show_bug.cgi?id=1328345 Source: XF Type: UNKNOWN pulp-cve20137450-mitm(112328) Source: CCN Type: Pulp GIT Repository 1003326 - generate pulp CA on initial install. #627 Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://github.com/pulp/pulp/pull/627 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||