6.8
CVSSv2

CVE-2015-5263

Published: 25/09/2017 Updated: 05/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

pulp-consumer-client 2.4.0 up to and including 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pulpproject pulp 2.4.0

pulpproject pulp 2.4.2

pulpproject pulp 2.4.4

pulpproject pulp 2.4.1

pulpproject pulp 2.4.3

pulpproject pulp 2.5.1

pulpproject pulp 2.5.2

pulpproject pulp 2.5.3

pulpproject pulp 2.5.0

pulpproject pulp 2.6.2

pulpproject pulp 2.6.3

pulpproject pulp 2.6.0

pulpproject pulp 2.6.1