← Vulnerability feed

Vulnerability record · CVE-2012-6119 · published 2 April 2013

CVE-2012-6119: Candlepinproject candlepin permissions and access controls vulnerability

Candlepinproject · Candlepin

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

2.1 CVSS 2.0 Low EPSS 0.42% · top 65.6% CWE-264 · Permissions and access controls
2.1CVSS 2.0 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

AV:L/AC:L/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-6119 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0130Ruby on Rails implicit-render directory traversal allows arbitrary file readRuby on Rails versions before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1 contain a directory traversal flaw in the implicit-render implementa…KEVEPSS 54%analysed9.8CVE-2015-7501Red Hat JBoss Java deserialization allows remote command executionMultiple Red Hat JBoss products deserialize untrusted Java objects and, through the Apache Commons Collections library, allow remote attackers to exe…EPSS 86%analysed9.3CVE-2013-6439Redhat subscription asset manager improper authentication vulnerabilityCandlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a sche…EPSS 1.6%8.1CVE-2023-1832Candlepinproject candlepin improper access control vulnerabilityAn improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…EPSS 0.59%7.5CVE-2012-6685Nokogiri vulnerabilityNokogiri before 1.5.4 is vulnerable to XXE attacksEPSS 2.2%6.5CVE-2014-0026Redhat subscription asset manager cross-site request forgery vulnerabilitykatello-headpin is vulnerable to CSRF in REST APIEPSS 0.43%6.5CVE-2013-6461Nokogiri vulnerabilityNokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limitsEPSS 2.2%6.5CVE-2013-6460Nokogiri vulnerabilityNokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documentsEPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2012-6119), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.